React2Shell exploit continues to escalate, posing ‘significant risk’


  • React2Shell (CVE-2025-55182) exploited to compromise hundreds of systems worldwide
  • China-affiliated groups and North Korea are exploiting bugs for persistence, espionage, and cryptomining
  • Patch immediately to React version 19.0.1, 19.1.2 or 19.2.1.

React2Shell, a critical severity vulnerability in React Server Components (RCS), was already used to compromise “several hundred machines across a variety of organizations”.

This is according to Microsoft, whose latest blog post discusses the vulnerability and how to defend against incoming attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top