Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch
First seen 27 Feb 2026, 20:12 UTC
•
•79% similarity
•62.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting applications built with React and Next.js. Users are urged to apply patches immediately to mitigate potential exploitation.
ThreatCluster AI
How this analysis works
Timeline
2025-01-05
CVE-2025-66478 published
2026-02-24
Article 2 published detailing the vulnerability
2026-02-27
Article 1 published urging immediate patching