


Perceptive Security
SOC/SIEM Consultancy

React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
Published:
6 December 2025 at 19:07:33
Alert date:
6 December 2025 at 20:00:56
Source:
bleepingcomputer.com

Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182). Attackers have already exploited this vulnerability to compromise over 30 organizations across multiple sectors. The flaw allows remote code execution and has been actively exploited in the wild. Security researchers have confirmed widespread exposure and active exploitation campaigns targeting vulnerable systems. Organizations are urged to patch immediately due to the critical nature and active exploitation of this vulnerability.
Technical details
Mitigation steps:
Affected products:
React2Shell
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.