Skip to content
Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch

Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch

First seen 27 Feb 2026, 20:12 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting applications built with React and Next.js. Users are urged to apply patches immediately to mitigate potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

Timeline

2025-01-05
CVE-2025-66478 published
2026-02-24
Article 2 published detailing the vulnerability
2026-02-27
Article 1 published urging immediate patching

More articles in this cluster (3)

Following this threat?

Track CVE-2025-66478 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed