Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

Multiple threat actors actively exploit critical React2Shell RCE vulnerability (CVE-2025-55182) in React components.

Summary written by editorial AI · Source link below

Filed by Mandiant Blog1 min readCVE-2025-55182Read at source ↗
CVSS10.0criticalCVE-2025-55182

Written by: Aragorn Tseng, Robert Weiner, Casey Charrier, Zander Work, Genevieve Stark, Austin Larsen Introduction On Dec. 3, 2025, a critical unauthenticated remote code execution (RCE) vulnerability in React Server Components, tracked as CVE-2025-55182 (aka "React2Shell"), was publicly disclosed. Shortly after disclosure, Google Threat Intelligence Group (GTIG) had begun observing widespread exploitation across many threat clusters, ranging from opportunistic cyber crime actors to suspected es

Continue at the source
Read the full report at Mandiant Blog

External link — opens at Mandiant Blog in a new tab.

§
Continue with

More from the Vulnerabilities Desk