Attackers Exploit React2Shell Vulnerability in IT and E-commerce Sectors
First seen 27 Jan 2026, 18:50 UTC
•
•30
Export
Article Content
Browse articles
Threat actors are exploiting a critical vulnerability known as React2Shell (CVE-2025-55182) to target companies in the insurance, e-commerce, and IT sectors. This vulnerability arises from insecure deserialization in the Flight protocol used for React Server Components, allowing unauthorized code execution on affected servers.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical React2Shell RCE Vulnerability Exploited in the Wild
RondoDox Botnet Targets React2Shell Flaw to Spread Malware
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
AWS Warns of Data Exfiltration Risks from Outbound Traffic Blind Spots
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits
Rapid Exploitation of Vulnerabilities in 2025: Insights from Cisco Talos