ThreatCluster

CISA Alerts on React Native Command Injection Vulnerability Exploited in Attacks

First seen 6 Feb 2026, 14:53 UTC Cybersecuritynews 100% similarity 32

Article Content

Browse articles
ThreatCluster

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-11953 to its Known Exploited Vulnerabilities catalog, identifying an OS command injection flaw in the React Native Community CLI that is actively being exploited. The vulnerability was added on February 5, 2026, with a federal patching deadline set for February 26, 2026.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story