2.15M Next.js Web Services Exposed, Active Exploitation Ongoing
First seen 6 Dec 2025, 09:47 UTC
•
•24
Export
Article Content
Browse articles
Over 2.15 million web services utilizing Next.js have been exposed on the internet, leading to active exploitation. The vulnerability has prompted immediate concerns among developers and organizations relying on this framework. Technical details regarding the nature of the exploitation have not been disclosed.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Automated Credential Harvesting Campaign Targets React2Shell Vulnerability
Critical Vulnerabilities in React and Next.js Require Immediate Updates
Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch
Critical React Flaw CVE-2025-55182 Exposes Major Security Risks
RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers
Operation PCPcat Compromises Over 59,000 Next.js/React Servers