React2Shell exploitation continues to escalate, posing “significant risk”


  • React2Shell (CVE‑2025‑55182) exploited to compromise hundreds of systems worldwide
  • Groups linked to China and North Korea exploit vulnerability for persistence, espionage and cryptomining
  • Patch immediately to React versions 19.0.1, 19.1.2, or 19.2.1.

React2Shell, a critical severity vulnerability in React Server Components (RCS), has already been used to compromise “several hundred machines across a diverse set of organizations.”

This is according to Microsoft, whose latest blog post discusses the vulnerability and how to defend against incoming attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top