Skip to content
ThreatCluster

Attackers Exploit React2Shell Vulnerability in IT and E-commerce Sectors

First seen 27 Jan 2026, 18:50 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Threat actors are exploiting a critical vulnerability known as React2Shell (CVE-2025-55182) to target companies in the insurance, e-commerce, and IT sectors. This vulnerability arises from insecure deserialization in the Flight protocol used for React Server Components, allowing unauthorized code execution on affected servers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track React2Shell and CVE-2025-55182 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed