Tag: Forcing Emergency Mitigation

React2Shell Exploitation Escalates into Large-Scale Global Attacks Forcing Emergency Mitigation
News

React2Shell Exploitation Escalates into Large-Scale Global Attacks Forcing Emergency Mitigation

Due to indications of extensive exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to patch the latest React2Shell vulnerability by December 12, 2025. The React Server Components (RSC) Flight protocol is impacted by the major vulnerability, identified as CVE-2025-55182 (CVSS score: 10.0). Unsafe deserialization, which enables an attacker to insert malicious code that the server runs in a privileged context, is the root cause of the problem. Other frameworks, such as Next.js, Waku, Vite, React Router, and RedwoodSDK, are also impacted. According to Cloudforce One, Cloudflare's threat intelligence team, a single, carefully constructed HTTP request is adequate; there is no need for user interaction, authentication, or higher permis...