CVE-2025-66478 is a vulnerability tracked across 6 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed December 3, 2025; most recent activity February 27, 2026.
A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting…
A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…
Burp Suite has upgraded its scanning capabilities to detect critical React2Shell vulnerabilities in JavaScript applications. Both editions of Burp Suite now include the latest detection logic, allowing users to validate…
Operation PCPcat has compromised 59,128 Next.js and React servers in under 48 hours, exploiting critical vulnerabilities CVE-2025-29927 and CVE-2025-66478. The attackers utilized prototype pollution in JSON payloads to…
The PCPcat malware campaign has compromised more than 59,000 servers in under 48 hours by exploiting critical vulnerabilities in .js and React frameworks. It specifically targets vulnerabilities CVE-2025-29927 and…
The 0G Foundation experienced a security breach on December 5, 2025, due to a critical vulnerability in .js (CVE-2025-66478). The attacker exploited the emergency withdrawal function of the 0G reward contract, resulting…