CISA Alerts on React Native Command Injection Vulnerability Exploited in Attacks
First seen 6 Feb 2026, 14:53 UTC
•
•100% similarity
•32
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-11953 to its Known Exploited Vulnerabilities catalog, identifying an OS command injection flaw in the React Native Community CLI that is actively being exploited. The vulnerability was added on February 5, 2026, with a federal patching deadline set for February 26, 2026.
ThreatCluster AI
How this analysis works