Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityrapid-weaponizationopen-source-dependency-vulnerabilitybotnet-infrastructure

React2Shell Remote Code Execution Vulnerability in React 19 and Next.js

Updated 3mo agoFirst seen Dec 29, 202511 sources

A critical remote code execution vulnerability, dubbed React2Shell, was discovered in the React 19 library, specifically affecting React Server Components. The flaw allows unauthenticated attackers to execute arbitrary code on servers by sending crafted requests, making it a severe risk for organizations using default React and Next.js deployments. Within hours of public disclosure, security firms including Google’s Threat Intelligence Group and AWS confirmed active exploitation in the wild, highlighting the shrinking window between vulnerability awareness and real-world attacks. Researchers from Wiz and Unit 42 demonstrated that even clean, default deployments were susceptible, emphasizing the widespread impact due to the popularity of these frameworks.

Threat actors rapidly weaponized the React2Shell vulnerability, with the RondoDoX botnet launching automated exploitation campaigns targeting both web applications and IoT devices. CloudSEK’s analysis of command and control logs revealed a multi-month campaign, with a significant spike in attacks following the vulnerability’s disclosure in December 2025. The RondoDoX botnet deployed various payloads, including web shells and cryptominers, and quickly adapted its infrastructure in response to security firm reports. Organizations with technology stacks overlapping the targeted vectors were promptly alerted, underscoring the urgent need for patching and monitoring in environments using React 19 and Next.js.

Share:
React2Shell Remote Code Execution Vulnerability in React 19 and Next.js
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Dec 31, 20256mo ago

CISA adds CVE-2025-55182 to the KEV catalog

By December 31, 2025, reporting noted that CISA had added CVE-2025-55182 to its Known Exploited Vulnerabilities catalog. The listing underscored that the flaw was actively exploited and required urgent remediation.

State-linked actors tied to React2Shell exploitation

Reporting in late December 2025 linked both criminal and state-aligned actors to React2Shell exploitation, including China-linked groups Earth Lumia and Jackpot Panda and North Korean operators. The flaw was described as being used for both initial access and persistent compromise.

Widespread exposure of vulnerable React2Shell systems reported

By late December 2025, researchers and internet scanning data reported tens of thousands of exposed vulnerable systems, with estimates ranging from about 77,000 in early December to more than 90,000 by the end of the month. Most exposed instances were reported in the United States.

Dec 29, 20256mo ago

Researchers confirm exploitation within hours of disclosure

Multiple vendors and researchers, including Google, AWS, Wiz, Unit 42, and Huntress, confirmed that React2Shell was exploited in the wild within hours of public disclosure. They also documented post-exploitation activity such as backdoors, tunneling tools, and cryptomining kits.

React and downstream frameworks release patches

React maintainers and downstream frameworks released patches for React2Shell and urged organizations to update immediately. Security guidance emphasized that patching should be paired with threat hunting because compromise could have already occurred.

React2Shell flaw is publicly disclosed as critical RCE

A critical unauthenticated remote code execution flaw in React 19 Server Components, tracked as CVE-2025-55182 and dubbed React2Shell, was publicly disclosed in December 2025. The bug affected default React and Next.js deployments and was rated CVSS 10.0.

Dec 13, 20256mo ago

Attackers shift infrastructure after React2Shell exposure

After Darktrace's December 10 reporting, RondoDox operators changed infrastructure, and CloudSEK observed new active command-and-control servers three days later. This indicated rapid adaptation to public scrutiny while continuing exploitation.

RondoDox begins repeated React2Shell attacks

CloudSEK observed exploitation of the Next.js/React Server Components flaw becoming the dominant RondoDox vector from December 13, 2025 onward. The botnet repeatedly delivered payloads including coinminers, Mirai-related binaries, and persistence tooling.

Dec 10, 20257mo ago

React2Shell exploitation publicly reported by Darktrace

CloudSEK said Darktrace publicly reported exploitation of React2Shell on December 10, 2025. This was an early public indication that attackers were already abusing the flaw in the wild.

Nov 1, 20258mo ago

RondoDox shifts to large-scale automated IoT deployment

By late 2025, the campaign had progressed from reconnaissance and web exploitation into hourly automated attacks that deployed botnet malware to IoT devices. Reports describe this as a distinct operational phase focused on scale, persistence, and propagation.

Jul 1, 20251y ago

Fortinet first identifies RondoDox botnet activity

BleepingComputer said Fortinet first identified RondoDox in July 2025. By that point, the botnet had already been evolving its operations against exposed infrastructure.

Mar 1, 20251y ago

RondoDox campaign begins reconnaissance and vulnerability testing

CloudSEK reported that the RondoDox botnet campaign started in March 2025 with reconnaissance and manual vulnerability testing against web applications and internet-exposed devices. This marked the first phase of a broader automated operation that later expanded to web servers and IoT targets.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

47 LINKEDOpen in app
Affected products
8 linked
Next.JsNext.JsWordpressReactOracle Weblogic ServerWeblogic ServerWeblogic ServerWeblogic Server
Organizations
26 linked
CloudSEKLinksysTP-LinkD-LinkNetgearASUSFortinetTrend MicroPalo Alto NetworksWatchGuard TechnologiesSonicwallRewterzWavlinkMeta PlatformsDarktraceAmazon Web ServicesShadowServer FoundationVulnCheckTP-Link TechnologiesPatrowlKasperskyDeepwatchHuntressWizRescanaGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.