Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityrapid-weaponizationinternet-facing-service-vulnerabilityproof-of-concept-release

React2Shell RCE in React Server Components Drives Mass Server Compromise

Updated 29d agoFirst seen May 25, 20269 sources

Threat actors are actively exploiting React2Shell, a critical remote code execution flaw in React Server Components tracked as CVE-2025-55182, with related exposure also noted in Next.js as CVE-2025-66478. The bug stems from insecure deserialization in the React Server Components Flight protocol and allows unauthenticated attackers to upload malicious payloads and execute arbitrary code on vulnerable internet-facing servers. Public disclosure was quickly followed by advisories, proof-of-concept code, and reports of broad exploitation, while Microsoft and other researchers said hundreds of machines had already been hacked.

Follow-on campaigns have been widespread and largely opportunistic, ranging from credential-harvesting operations to malware deployment against organizations in multiple sectors and regions. Cisco Talos-linked reporting said at least 766 servers were compromised by an automated campaign that stole SSH keys, cloud tokens, API keys, Kubernetes and GitHub credentials, Docker metadata, and other environment secrets, including keys tied to AI platforms and payment services. Other investigations tied exploitation to XMRig, RustoBot, Kaiji, Sliver, CrossC2, Tactical RMM, VShell, and EtherRAT, along with persistence, reconnaissance, DNS-based exfiltration, and SSH key installation, underscoring how rapidly the vulnerability was weaponized after disclosure.

Share:
React2Shell RCE in React Server Components Drives Mass Server Compromise
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Apr 3, 20263mo ago

Cisco Talos links React2Shell to automated credential-harvesting campaign

Cisco Talos reported a widespread automated campaign exploiting internet-facing vulnerable React Server Components instances, attributing activity to UAT-10608. The payload harvested credentials, SSH keys, cloud tokens, API keys, and other secrets, with at least 766 servers compromised across multiple regions.

Feb 4, 20265mo ago

Threat activity around React2Shell undergoes a significant shift

Reporting in early February 2026 indicated a notable change in how threat actors were exploiting React2Shell. This suggests the campaign evolved beyond its initial exploitation patterns.

Dec 18, 20256mo ago

Microsoft reports hundreds of machines hacked via React2Shell

By mid-December, Microsoft counted hundreds of compromised machines tied to React2Shell exploitation, indicating the campaign had scaled significantly. This represented a major escalation in observed impact.

Dec 15, 20256mo ago

Attackers exploit React2Shell against organizations in December 2025

BI.ZONE reported that adversaries exploited React2Shell during December 2025, including attacks on Russian companies in the insurance, e-commerce, and IT sectors. Observed post-exploitation included XMRig, RustoBot, Kaiji, Sliver, CrossC2, Tactical RMM, VShell, EtherRAT, persistence, and DNS-based exfiltration.

Dec 8, 20257mo ago

Active exploitation of React2Shell is reported

Threat researchers reported that CVE-2025-55182 was being actively exploited in the wild. This established that the vulnerability had moved from disclosure into real-world attacks.

Dec 5, 20257mo ago

JPCERT/CC issues advisory on React Server Components flaw

JPCERT/CC published an advisory covering CVE-2025-55182 in React Server Components. The advisory reflects formal defender awareness and guidance around the vulnerability.

Proof-of-concept exploit for React2Shell is released on GitHub

A GitHub repository published a proof-of-concept script for CVE-2025-55182, demonstrating exploitation of the React SSR/RSC remote code execution flaw. Public exploit code likely lowered the barrier for attackers to weaponize the bug.

Dec 4, 20257mo ago

Researchers publish broader technical analysis of React2Shell and related CVEs

A detailed write-up described React2Shell as a critical RCE affecting React Server Components and Next.js, including CVE-2025-55182 and CVE-2025-66478. The publication expanded public technical understanding of the flaw and affected ecosystem.

Dec 3, 20257mo ago

CVE-2025-55182 vulnerability record is published

A public CVE entry for CVE-2025-55182 appeared, identifying the React Server Components server-side remote code execution issue later dubbed React2Shell. This marks the earliest public disclosure point visible in the references.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.