Cybersecuritydive
Escalation of React2Shell Exploitation Following CVE-2025-55182 Disclosure
First seen 4 Feb 2026, 22:55 UTC
•


•25.0
Export
Article Content
Browse articles
A critical vulnerability in React Server Components, identified as CVE-2025-55182, was publicly disclosed on December 3, 2025. Following its disclosure, exploitation activity has increased significantly, affecting millions of developers who are urged to patch to secure versions 19.0.1, 19.1.2, or 19.2.1 to mitigate risks. The vulnerability was added to the CISA KEV list on December 5, 2025, indicating active exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical React2Shell RCE Vulnerability Exploited in the Wild
RondoDox Botnet Targets React2Shell Flaw to Spread Malware
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
AWS Warns of Data Exfiltration Risks from Outbound Traffic Blind Spots
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits
Rapid Exploitation of Vulnerabilities in 2025: Insights from Cisco Talos