Skip to content

CVE-2025-66478

CVE

Threat entity extracted from intelligence sources

Frequency
16
occurrences
First Seen
December 3, 2025
Last Seen
February 27, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting applications built with React and Next.js. Users are urged to apply patches imme...

A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud environments are vulnerable, and exploitation is expected to occur imminently. Develop...

Burp Suite has upgraded its scanning capabilities to detect critical React2Shell vulnerabilities in JavaScript applications. Both editions of Burp Suite now include the latest detection logic, allowing users to validate their exposure and perform automated scans effectively.

Operation PCPcat has compromised 59,128 Next.js and React servers in under 48 hours, exploiting critical vulnerabilities CVE-2025-29927 and CVE-2025-66478. The attackers utilized prototype pollution in JSON payloads to achieve a 64.6% success rate across 91,505 scanned targets, deploying PCPCat scan...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Articles (16)

1 / 4