Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch

Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch

First seen 27 Feb 2026, 20:12 UTC YoutubeGist.Github 79% similarity 62.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting applications built with React and Next.js. Users are urged to apply patches immediately to mitigate potential exploitation.

ThreatCluster AI How this analysis works

Timeline

2025-01-05
CVE-2025-66478 published
2026-02-24
Article 2 published detailing the vulnerability
2026-02-27
Article 1 published urging immediate patching

Community

Browse all →

Tracked Entities in This Story