SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,981 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,981 new IOCs ingested in last 24h

CVE-2025-55182

⚡ CISA KEV🔐 Ransomware
Published: Modified: Vendor: MetaProduct: React Server Components
CVSS v3
99.6%
EPSS
⚡ Added to KEV on 2025-12-05 · Federal agencies must remediate by 2025-12-12
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
💣 Public Exploits1
From Exploit-DB
React Server 19.2.0 - Remote Code Executionmultiplewebapps2026-04-09
🔍 Sigma Detection Rules2
Rules tagged with this CVE
highLinux Suspicious Child Process from Node.js - React2Shelllinux
highWindows Suspicious Child Process from Node.js - React2Shellwindows
🛠️ Patch Details20
Affected/fixed versions from threat intel reports
React2Shellsource ↗
React Server Componentssource ↗
OpenClawsource ↗
Recorded Future Attack Surface Intelligencesource ↗
Meta ReactReact < 19.0.1; Next.js multiple linessource ↗
Next.jssource ↗
React19.1.0source ↗
Next.js15.4.6source ↗
Baota Baota (BT) management panelsource ↗
NGINXsource ↗
Google Chromesource ↗
Reactsource ↗
React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack)version 19.0, 19.1.0, 19.1.1, and 19.2.0versions 19.0.1, 19.1.2, and 19.2.1source ↗
Vercel Next.jssource ↗
Parcel Parcel RSCsource ↗
Vite Vite RSC pluginsource ↗
React Router React Router (unstable RSC APIs)source ↗
Vercel Next.jssource ↗
React react-server-dom-turbopack19.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1source ↗
React react-server-dom-parcel19.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1source ↗
📰 Threat Intel Coverage20
Digest reports mentioning this CVE
No Manners Here: The Ruthless Rise of The Gentlemen Ransomwareunit422026-07-10
Vect and TeamPCP partner for ransomware campaignssophos.threat_research2026-07-02
Security risks for OpenClaw users and how to mitigate these riskssecurelist2026-07-01
Splunk Enterprise RCE (CVE-2026-20253) | ThreatLabzzscaler.threatlabz2026-06-26
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257unit422026-06-09
How Huntress Uses Managed SIEM to Detect Threats Faster | Huntresshuntress2026-05-21
At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026recordedfuture2026-05-19
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scalesentinellabs2026-05-07
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Executionunit422026-05-07
Copy Fail: What You Need to Know About the Most Severe Linux Threat in Yearsunit422026-05-05
Untangling a Linux Incident With an OpenAI Twist (Part 2) | Huntresshuntress2026-04-22
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting - The DFIR Reportthedfirreport2026-04-22
A Deep Dive Into Attempted Exploitation of CVE-2023-33538unit422026-04-16
Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaignhawkeye2026-02-06
Dissecting CrashFix: KongTuke's New Toy | Huntresshuntress2026-01-16
Tradecraft Tuesday Recap | Huntresshuntress2025-12-23
Gladinet CentreStack/Triofox: Cryptography Vulnerability | Huntresshuntress2025-12-18
PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182 | Huntresshuntress2025-12-10
Critical RCE Vulnerability in React Server Components – CVE-2025-55182hawkeye2025-12-06
Wing FTP Server RCE (CVE-2025-47812) Exploited in the Wild | Huntresshuntress2025-07-10
📎 References0
No reference URLs.