Escalation of React2Shell Exploitation Following CVE-2025-55182 Disclosure

Escalation of React2Shell Exploitation Following CVE-2025-55182 Disclosure

First seen 4 Feb 2026, 22:55 UTC DarkreadingTechradarCybersecuritydiveGbhackers 25.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in React Server Components, identified as CVE-2025-55182, was publicly disclosed on December 3, 2025. Following its disclosure, exploitation activity has increased significantly, affecting millions of developers who are urged to patch to secure versions 19.0.1, 19.1.2, or 19.2.1 to mitigate risks. The vulnerability was added to the CISA KEV list on December 5, 2025, indicating active exploitation.