


Perceptive Security
SOC/SIEM Consultancy

Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation
Published:
6 december 2025 om 11:40:00
Alert date:
6 december 2025 om 12:00:57
Source:
thehackernews.com

CISA has added a critical React Server Components vulnerability (CVE-2025-55182) to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw has a maximum CVSS score of 10.0 and allows for remote code execution, making it extremely dangerous for organizations using React Server Components. The vulnerability has been dubbed 'React2Shell' and represents a significant threat to web applications built with React.
Technical details
Mitigation steps:
Affected products:
React Server Components
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.