CVE-2025-55182Active Exploitation(facebook / next.js)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 42 mentions and remains active

Immediate actions

  • Patch facebook next.js systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js
  • react

Threat summary

  • Active exploitation appears in 247 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 398 mentions across 133 observed days

What's happening

  • Active exploitation reported across 247 signals
  • Exploit tool or code specified in 53 signals
  • PoC mentioned or linked in 47 signals
  • Patch or workaround mentioned in 74 signals
  • Technical details provided in 153 signals
  • General: 63 classified signals
  • Disclosure: 32 classified signals
  • Peaked 81d ago at 42 mentions (2026-04-03); latest day: 1
  • 398 total mentions across 133 days

Affected systems

Products
next.jsreact

7 versions affected across 2 products

Deep dive

Activity timeline398 mentions / 133d
011213242Mentions · 2026-01-27: 2Mentions · 2026-01-28: 7Mentions · 2026-01-29: 6Mentions · 2026-01-30: 5Mentions · 2026-02-01: 2Mentions · 2026-02-02: 2Mentions · 2026-02-03: 3Mentions · 2026-02-04: 14Mentions · 2026-02-05: 7Mentions · 2026-02-06: 3Mentions · 2026-02-08: 2Mentions · 2026-02-09: 4Mentions · 2026-02-10: 6Mentions · 2026-02-11: 4Mentions · 2026-02-12: 4Mentions · 2026-02-13: 2Mentions · 2026-02-14: 2Mentions · 2026-02-15: 3Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 3Mentions · 2026-02-20: 3Mentions · 2026-02-22: 1Mentions · 2026-02-23: 2Mentions · 2026-02-24: 2Mentions · 2026-02-25: 2Mentions · 2026-02-26: 1Mentions · 2026-02-27: 4Mentions · 2026-03-01: 1Mentions · 2026-03-03: 4Mentions · 2026-03-04: 2Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 7Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 3Mentions · 2026-03-22: 5Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 4Mentions · 2026-04-02: 33Mentions · 2026-04-03: 42Mentions · 2026-04-04: 7Mentions · 2026-04-05: 13Mentions · 2026-04-06: 11Mentions · 2026-04-07: 9Mentions · 2026-04-08: 6Mentions · 2026-04-09: 3Mentions · 2026-04-10: 3Mentions · 2026-04-11: 3Mentions · 2026-04-12: 1Mentions · 2026-04-13: 2Mentions · 2026-04-14: 3Mentions · 2026-04-15: 5Mentions · 2026-04-16: 3Mentions · 2026-04-18: 2Mentions · 2026-04-19: 1Mentions · 2026-04-20: 4Mentions · 2026-04-22: 4Mentions · 2026-04-23: 1Mentions · 2026-04-24: 3Mentions · 2026-04-25: 1Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-04-30: 2Mentions · 2026-05-01: 1Mentions · 2026-05-02: 2Mentions · 2026-05-05: 3Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Mentions · 2026-05-08: 2Mentions · 2026-05-09: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-13: 2Mentions · 2026-05-15: 1Mentions · 2026-05-19: 2Mentions · 2026-05-20: 1Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1Mentions · 2026-05-25: 2Mentions · 2026-05-29: 1Mentions · 2026-06-01: 1Mentions · 2026-06-02: 1Mentions · 2026-06-03: 2Mentions · 2026-06-04: 3Mentions · 2026-06-19: 1Mentions · 2026-06-22: 1Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Mentions · 2026-07-02: 1Mentions · 2026-07-08: 2Mentions · 2026-07-12: 1Mentions · 2026-07-22: 1Mentions · 2026-07-23: 1Mentions · 2026-07-24: 1Mentions · 2026-07-26: 1Mentions · 2026-07-31: 1Mentions · 2026-08-02: 1Mentions · 2026-08-03: 2Mentions · 2026-08-07: 1Mentions · 2026-08-11: 1Mentions · 2026-08-17: 2Mentions · 2026-08-18: 2Mentions · 2026-08-22: 2Mentions · 2026-08-25: 2Mentions · 2026-08-27: 1Mentions · 2026-08-29: 2Mentions · 2026-09-08: 2Mentions · 2026-09-09: 2Mentions · 2026-09-11: 1Mentions · 2026-09-21: 3Mentions · 2026-09-22: 3Mentions · 2026-09-23: 1Mentions · 2026-09-29: 1Mentions · 2026-09-30: 3Mentions · 2026-10-02: 1Mentions · 2026-10-04: 1Mentions · 2026-10-06: 3Mentions · 2026-10-08: 5Mentions · 2026-10-09: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-02-05: 3PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-02: 2PoC Mentioned / Linked · 2026-04-03: 3PoC Mentioned / Linked · 2026-04-06: 3PoC Mentioned / Linked · 2026-04-07: 2PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-14: 2PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-06-01: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-07-08: 2PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-29: 1PoC Mentioned / Linked · 2026-09-08: 1PoC Mentioned / Linked · 2026-09-09: 2PoC Mentioned / Linked · 2026-09-11: 1PoC Mentioned / Linked · 2026-09-21: 1PoC Mentioned / Linked · 2026-09-22: 1PoC Mentioned / Linked · 2026-09-30: 1Exploit Tool / Code · 2026-01-28: 1Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-02-05: 3Exploit Tool / Code · 2026-02-08: 1Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-02-10: 2Exploit Tool / Code · 2026-02-11: 2Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-02-18: 1Exploit Tool / Code · 2026-02-23: 1Exploit Tool / Code · 2026-03-03: 1Exploit Tool / Code · 2026-03-04: 1Exploit Tool / Code · 2026-03-09: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-03-22: 1Exploit Tool / Code · 2026-03-25: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-02: 2Exploit Tool / Code · 2026-04-03: 3Exploit Tool / Code · 2026-04-05: 2Exploit Tool / Code · 2026-04-06: 3Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-04-22: 2Exploit Tool / Code · 2026-04-23: 1Exploit Tool / Code · 2026-04-24: 1Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-22: 1Exploit Tool / Code · 2026-06-01: 1Exploit Tool / Code · 2026-06-04: 1Exploit Tool / Code · 2026-07-08: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-18: 1Exploit Tool / Code · 2026-08-22: 1Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-08-27: 1Exploit Tool / Code · 2026-08-29: 1Exploit Tool / Code · 2026-09-08: 1Exploit Tool / Code · 2026-09-09: 1Exploit Tool / Code · 2026-09-21: 1Exploit Tool / Code · 2026-09-30: 1Active Exploitation · 2026-01-27: 2Active Exploitation · 2026-01-28: 5Active Exploitation · 2026-01-29: 3Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-03: 3Active Exploitation · 2026-02-04: 11Active Exploitation · 2026-02-05: 5Active Exploitation · 2026-02-06: 2Active Exploitation · 2026-02-08: 2Active Exploitation · 2026-02-09: 3Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-11: 3Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-15: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-02-19: 2Active Exploitation · 2026-02-20: 2Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-24: 2Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-03: 2Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-09: 4Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 2Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-19: 2Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-04-01: 3Active Exploitation · 2026-04-02: 32Active Exploitation · 2026-04-03: 38Active Exploitation · 2026-04-04: 7Active Exploitation · 2026-04-05: 12Active Exploitation · 2026-04-06: 9Active Exploitation · 2026-04-07: 7Active Exploitation · 2026-04-08: 4Active Exploitation · 2026-04-09: 2Active Exploitation · 2026-04-10: 2Active Exploitation · 2026-04-13: 2Active Exploitation · 2026-04-14: 3Active Exploitation · 2026-04-15: 2Active Exploitation · 2026-04-16: 2Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-20: 4Active Exploitation · 2026-04-22: 3Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-24: 3Active Exploitation · 2026-04-25: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-05-05: 2Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-08: 2Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-13: 2Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-04: 3Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-22: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-23: 1Active Exploitation · 2026-07-26: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-22: 1Active Exploitation · 2026-08-27: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-01-30: 3Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 5Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-04-01: 2Patch / Workaround · 2026-04-02: 2Patch / Workaround · 2026-04-03: 7Patch / Workaround · 2026-04-05: 5Patch / Workaround · 2026-04-06: 5Patch / Workaround · 2026-04-07: 3Patch / Workaround · 2026-04-08: 2Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-07-24: 1Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-01-27: 2Technical Details · 2026-01-28: 3Technical Details · 2026-01-29: 4Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 9Technical Details · 2026-02-05: 3Technical Details · 2026-02-06: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 6Technical Details · 2026-02-11: 3Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-11: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 3Technical Details · 2026-04-02: 10Technical Details · 2026-04-03: 10Technical Details · 2026-04-05: 3Technical Details · 2026-04-06: 5Technical Details · 2026-04-07: 6Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-18: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-24: 1Technical Details · 2026-07-26: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-02: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-27: 1Technical Details · 2026-09-09: 2Technical Details · 2026-09-21: 1Technical Details · 2026-09-30: 101-2702-1102-2603-1604-0404-1805-0505-2307-1208-2510-0610-09
Signal classification7 categories
Active Exploitation
23862.0%
General
6316.4%
Disclosure
328.3%
Patch
205.2%
Exploit
174.4%
PoC
133.4%
Referenced assets278 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-272
Active Exploitation2
2026-01-287
Active Exploitation5Disclosure1General1
2026-01-296
Active Exploitation3Disclosure2General1
2026-01-305
Active Exploitation1General1Patch2PoC1
2026-02-012
Active Exploitation1Disclosure1
2026-02-022
General2
2026-02-033
Active Exploitation3
2026-02-0414
Active Exploitation11Disclosure1General2
2026-02-057
Active Exploitation5General2
2026-02-063
Active Exploitation2General1
2026-02-082
Active Exploitation2
2026-02-094
Active Exploitation3Disclosure1
2026-02-106
Active Exploitation2Disclosure2Exploit1Patch1
2026-02-114
Active Exploitation3General1
2026-02-124
Active Exploitation1Exploit1General2
2026-02-132
Active Exploitation1General1
2026-02-142
Active Exploitation1General1
2026-02-153
Active Exploitation1General2
2026-02-171
General1
2026-02-181
Active Exploitation1
2026-02-193
Active Exploitation2Patch1
2026-02-203
Active Exploitation2General1
2026-02-221
Active Exploitation1
2026-02-232
Exploit1General1
2026-02-242
Active Exploitation2
2026-02-252
Disclosure1General1
2026-02-261
Active Exploitation1
2026-02-274
Disclosure2General2
2026-03-011
General1
2026-03-034
Active Exploitation1General2Patch1
2026-03-042
Active Exploitation1Disclosure1
2026-03-062
Active Exploitation1General1
2026-03-071
Patch1
2026-03-081
Patch1
2026-03-097
Active Exploitation4Disclosure1General2
2026-03-101
Active Exploitation1
2026-03-112
Active Exploitation2
2026-03-121
General1
2026-03-131
Active Exploitation1
2026-03-161
Active Exploitation1
2026-03-171
Exploit1
2026-03-181
Patch1
2026-03-193
Active Exploitation2General1
2026-03-225
Disclosure1Exploit1General3
2026-03-241
Patch1
2026-03-251
Active Exploitation1
2026-03-261
General1
2026-03-271
Active Exploitation1
2026-03-312
Exploit1General1
2026-04-014
Active Exploitation3General1
2026-04-0233
Active Exploitation32General1
2026-04-0342
Active Exploitation38Exploit1False Positive1General2
2026-04-047
Active Exploitation7
2026-04-0513
Active Exploitation12Disclosure1
2026-04-0611
Active Exploitation9Disclosure1PoC1
2026-04-079
Active Exploitation7Disclosure1General1
2026-04-086
Active Exploitation4General1Patch1
2026-04-093
Active Exploitation2Patch1
2026-04-103
Active Exploitation2Disclosure1
2026-04-113
Disclosure1General1PoC1
2026-04-121
Disclosure1
2026-04-132
Active Exploitation1Exploit1
2026-04-143
Active Exploitation2Exploit1
2026-04-155
Active Exploitation2General1Patch1PoC1
2026-04-163
Active Exploitation2General1
2026-04-182
Disclosure1General1
2026-04-191
Active Exploitation1
2026-04-204
Active Exploitation4
2026-04-224
Active Exploitation3Disclosure1
2026-04-231
Active Exploitation1
2026-04-243
Active Exploitation3
2026-04-251
Active Exploitation1
2026-04-261
Active Exploitation1
2026-04-271
Active Exploitation1
2026-04-281
Active Exploitation1
2026-04-302
Active Exploitation1General1
2026-05-011
Active Exploitation1
2026-05-022
Active Exploitation1Patch1
2026-05-053
Active Exploitation2General1
2026-05-062
Active Exploitation1Disclosure1
2026-05-071
Patch1
2026-05-082
Active Exploitation2
2026-05-092
General1Patch1
2026-05-101
General1
2026-05-112
Active Exploitation1General1
2026-05-121
Active Exploitation1
2026-05-132
Active Exploitation2
2026-05-151
Patch1
2026-05-192
Disclosure1General1
2026-05-201
Patch1
2026-05-221
Active Exploitation1
2026-05-231
General1
2026-05-252
General1Patch1
2026-05-291
General1
2026-06-011
Exploit1
2026-06-021
General1
2026-06-032
Active Exploitation2
2026-06-043
Active Exploitation3
2026-06-191
Active Exploitation1
2026-06-221
Active Exploitation1
2026-06-291
PoC1
2026-06-301
Active Exploitation1
2026-07-021
Active Exploitation1
2026-07-082
PoC2
2026-07-121
PoC1
2026-07-221
General1
2026-07-231
Active Exploitation1
2026-07-241
Disclosure1
2026-07-261
Active Exploitation1
2026-07-311
Disclosure1
2026-08-021
Disclosure1
2026-08-032
Active Exploitation1Patch1
2026-08-071
Active Exploitation1
2026-08-111
General1
2026-08-172
Disclosure1PoC1
2026-08-182
Disclosure1Exploit1
2026-08-222
Active Exploitation1Patch1
2026-08-252
Exploit1General1
2026-08-271
Exploit1
2026-08-292
Disclosure1PoC1
2026-09-082
Exploit1General1
2026-09-092
PoC2
2026-09-111
Exploit1
2026-09-213
Disclosure2Exploit1
2026-09-223
General2PoC1
2026-09-231
General1
2026-09-303
Exploit1
Full discourse20 posts
  • yousukezan@yousukezan
    Active Exploitation

    Next.jsの重大欠陥を悪用した大規模侵害が発覚し、数百台規模のサーバーからクラウド認証情報や秘密鍵が窃取される事態となった。攻撃は自動化され広範囲に拡散している。 この攻撃はCVE-2025-55182を悪用し、React Server Componentsの脆弱性からリモートコード実行を実現する。侵入後は「NEXUS Listener」と呼ばれる収集基盤を展開し、環境変数やSSH鍵、AWSやGCP、Azureの認証情報、APIキー、データベース接続情報などを自動収集する。収集データはGUI付きC2で管理され、侵害台数や取得情報が可視化される仕組みである。少なくとも766台が侵害され、Shodanなどを用いたスキャンで脆弱なNext.js環境が無差別に狙われたとみられる。取得された情報にはStripeやGitHubなどのトークンも含まれ、二次攻撃や不正アクセスの踏み台として悪用される危険が高い。対策として権限最小化や認証情報のローテーションが求められる。 https://thehackernews.com/2026/04/hackers-exploit-cve-2025-55182-to.html

    Post summary

    CVE‑2025‑55182 is actively exploited in an automated large‑scale breach, allowing attackers to execute code and harvest credentials from hundreds of Next.js/React Server Components deployments.

    316017681463100.9K
    14.3K followersView on X
  • VLadimiR@Dz10Chiheb
    Disclosure

    CVE-2025-55182 RCE on Next.js 16.0.6 #CVE https://t.co/9lf4cj6Mwj

    Post summary

    A new CVE (CVE-2025-55182) is announced, revealing a remote code execution flaw in Next.js version 16.0.6.

    854861932789.7K
    431 followersView on X
  • ︎︎🐸いまいまい🐌@imaimai17468
    Patch

    2026年4月8日、React Server Components に新たな脆弱性(CVE-2026-23869)が公開されました。CVSS スコアは 7.5 で、深刻度は高に分類されます。 何が起きたか Next.js の App Router が使用する React Server Components の処理に欠陥があります。攻撃者が細工した HTTP リクエストを App Router の Server Function エンドポイントに送信すると、デシリアライズ時にサーバーの CPU 使用率が異常に上昇し、サービスが停止する可能性があります。認証は不要で、外部から攻撃を行うことができます。対象は Next.js 13.x、14.x、15.x、16.x で App Router を使用しているアプリケーションです。Pages Router のみを使用している場合は影響を受けません。 2025年末の脆弱性との違い 2025年12月に公開された CVE-2025-55182(通称 React2Shell)は、同じ React Server Components の仕組みを悪用するものでしたが、サーバー上で任意のコードを実行できる脆弱性でした。深刻度は最高値の CVSS 10.0 で、実際に悪用された事例も報告されています。今回の CVE-2026-23869 はコードの実行には至らず、サービスの停止にとどまります。根本的な原因は同じデシリアライズ処理の設計にあり、React2Shell 以降も研究者による調査が続いた結果、関連する欠陥が順次発見されています。 対応すること Next.js を以下のバージョンに更新してください。15 系を使用している場合は 15.5.15 以降、16 系を使用している場合は 16.2.3 以降が修正済みのバージョンです。Vercel にホストしている場合は WAF による緩和措置が自動適用されていますが、バージョンアップの代替にはなりません。更新後は動作確認を行い、問題がなければ本番環境に適用してください。

    Post summary

    CVE-2026-23869 is a high‑severity denial‑of‑service flaw in Next.js React Server Components; the notice offers technical details and explicit patch guidance but no PoC or active exploitation evidence.

    21011755432491.1K
    5.9K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    This vulnerability allows RCE in React Server Functions, e.g. as offered by Next.js through insecure prototype references. CVE-2025-55182 https://t.co/bnw2BQIcMA

    Post summary

    The tweet announces that CVE‑2025‑55182 enables remote code execution via insecure prototype references in React Server Functions, specifically impacting Next.js implementations.

    128022210813.2K
    12.1K followersView on X
  • Koupon@Shabosec
    Exploit

    I DID IT AGAIN RCE LEAD TO ADMIN PAYMENT PORTAL🔥🔥🔥 Next.js will you marry me ❤️❤️ ❤️ Tips: I found the embedded link in the js which i input which turn on Notifications it’s Vulnerable to RCE Next.js RSC Exploit Tool (CVE-2025-55182) https://github.com/ynsmroztas/NextRce Yandex Dork🔥 https://t.co/q6waergibP

    Post summary

    The user claims to have exploited CVE‑2025‑55182 via an RCE in Next.js, shares a GitHub-based exploit tool, and reports gaining admin access to a payment portal.

    615214413212.3K
    1.8K followersView on X
  • Renzon@r3nzsec
    Active Exploitation

    I worked with @svch0st and @TheDFIRReport to put out a report in less than 24 hours. This is especially timely given the threat actor's use of OpenClaw and Claude in the mass exploitation of CVE-2025-55182 (React2Shell). An exposed open directory gave us the full operational footprint: scanner harness, AI-orchestrated post-exploitation, Telegram C2, and thousands of exfiltrated .env files across 900+ confirmed compromises. #Claude #OpenClaw #DFIR

    Post summary

    The post reports that threat actors are actively exploiting CVE‑2025‑55182, using AI‑driven tools to post‑exploit, exfiltrating .env files from over 900 compromised systems.

    52611064318.8K
    4.4K followersView on X
  • termireum@termireum
    General

    CVE-2025-55182 React2Shell #bugbounty https://t.co/PMXTwyIivb

    Post summary

    The tweet merely lists CVE-2025-55182 with a #bugbounty hashtag and a link, providing no substantive technical or operational details.

    34182345.4K
    756 followersView on X
  • The DFIR Report@TheDFIRReport
    Active Exploitation

    We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits. Logs showed an automated pipeline for exploitation, hit scoring, alerting, and secret harvesting. Claude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration. Read the full case: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/

    Post summary

    The article reports a large‑scale, ongoing exploitation campaign against CVE‑2025‑55182 using automated tools, with over 900 successful attacks.

    322056348.4K
    68.0K followersView on X
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    Two IPs now generate 56% of all CVE-2025-55182 exploitation traffic. One deploys cryptominers. The other opens reverse shells. We dug into the infrastructure. What we found goes back to 2020. https://www.greynoise.io/blog/react2shell-exploitation-consolidates

    Post summary

    Two IP addresses dominate the exploitation traffic for CVE‑2025‑55182, deploying cryptominers and establishing reverse shells, demonstrating active exploitation in the wild.

    012259347.4K
    29.3K followersView on X
  • X@SansLimit3
    Active Exploitation

    Exploitation infrastructure observed scanning for: CVE-2025-55182(React2shell) CVE-2026-21962(Oracle Weblogic) CVE-2025-31324(SAP NetWeaver) - actively exploited by China-linked APTs Targeting India-based critical infrastructure SAP exploit script "MADE BY SCATTERED LAPSUS$ HUNTERS" → likely tool reuse. Tooling includes fscan & Neo-reGeorg - commonly seen in China-linked intrusion tradecraft. C2s: 160[.]191.183.147:80 160[.]191.183.126:80 Seen on @Huntio ~ 1 month ago. @malwrhunterteam @polygonben @WhichbufferArda

    Post summary

    The report details scanning activity for several CVEs, noting that CVE-2025-31324 in SAP NetWeaver is actively exploited by China‑linked APTs, and references a known exploit script, but provides no patch info or in‑depth vulnerability specifics.

    27154244.6K
    231 followersView on X
  • Ctrl-Alt-Intel@ctrlaltintel
    Active Exploitation

    Recent find by our team using @Huntio🕵️‍♂️ Akia: Exploiting CVE-2025-55182/66478, this French Claude-coded pipeline is a massive secret harvester: 🔹13 Git/8 SMTP APIs 🔹3k+ AWS Keys 🔹250M JS URLs 🔹EVM/BTC/SOL 🔹250+ ENV types 🔹1k+ Cloud paths 🔹300+ Configs 🔹20+ Code exts https://t.co/U1lTYkltHR

    Post summary

    The tweet reports that a research team is actively exploiting CVE‑2025‑55182/66478 to harvest credentials and code from compromised systems.

    011150246.9K
    969 followersView on X
  • Unit 42@Unit42_Intel
    Active Exploitation

    React2Shell (CVE-2025-55182) was exploited within 2 days of public disclosure. Attackers executed commands in Kubernetes workloads, installing backdoors and stealing data. Application exploits lead to cluster compromise. Read our analysis: https://bit.ly/3Q4x50q https://t.co/g9y4qKI3s6

    Post summary

    CVE‑2025‑55182 was actively exploited within two days of its disclosure, enabling attackers to run arbitrary commands inside Kubernetes workloads, install backdoors, and steal data, posing a serious risk to containerized environments.

    117246207.0K
    69.4K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    Analysis of #Lazarus Campaign Exploiting CVE-2025-55182 and Copperhedge Malware This report analyzes an ongoing intrusion campaign launched by the notorious Lazarus Group, leveraging the high-risk unauthenticated remote code execution (RCE) vulnerability CVE-2025-55182 paired with the Copperhedge malware suite, targeting global financial institutions and blockchain infrastructure for financial theft and sensitive intelligence harvesting. https://mp.weixin.qq.com/s/3kwDMAXviaE1TUDnkYlqrg

    Post summary

    The report highlights an active Lazarus intrusion campaign exploiting CVE‑2025‑55182 via Copperhedge malware against financial institutions, confirming real‑world exploitation of the RCE vulnerability.

    016039193.3K
    42.9K followersView on X
  • andrew gao@itsandrewgao
    General

    remember the react2shell CVE from dec '25? so apparently the guy found it using deepwiki... (CVE-2025-55182) https://t.co/LXEbSP52LV

    Post summary

    The tweet merely references CVE-2025-55182 and notes its discovery via deepwiki, providing no further technical or operational details.

    3204895.9K
    43.7K followersView on X
  • Aircorridor@_aircorridor
    Active Exploitation

    React2Shell (CVE-2025-55182) is already being actively exploited against Next.js systems worldwide. Don’t just hear about it, understand it: https://hackers-arise.com/react2shell-vulnerability-exploited-to-build-massive-iot-botnet/ @three_cube @DI0256 @IamSmouk @co11ateral https://t.co/cnEKn1Fb1c

    Post summary

    The tweet confirms that CVE-2025-55182 (React2Shell) is being actively exploited in the wild, with a link pointing to a blog post discussing the exploitation.

    08021131.7K
    13.1K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    🚨 React2Shell Exploitation at Scale: 700+ Systems Breached in Global Campaign https://www.darkreading.com/cyberattacks-data-breaches/automated-credential-harvesting-campaign-react2shell A large-scale campaign is exploiting React2Shell (CVE-2025-55182) to compromise exposed Next.js apps and harvest credentials at scale. At least 766 systems across industries and cloud providers have been hit. Once inside, attackers deploy an automated framework to extract SSH keys, tokens, and secrets, turning breaches into searchable datasets. With automated scanning and zero auth required, the scope is extensive, and the stolen credentials can quickly be used to launch additional attacks. #ThreatIntelligence #ThreatHunting #CyberSecurity

    Post summary

    The report details a worldwide exploitation campaign against the CVE-2025‑55182 React2Shell vulnerability, impacting more than 766 Next.js applications and leading to large‑scale credential theft.

    07024102.2K
    6.3K followersView on X
  • Is Now on VT!@Now_on_VT
    Active Exploitation

    Sample is now on VT! 🚩Hash: ba43e447e63611d365300bf2e8e43ccb02ea112778d0d555ef9a9ccf6169808b 🎯Malware name: Multiple:React2shell 🔹Comment: Analysis of React Server Components RCE vulnerability (CVE-2025-55182) exploitation leading to cryptojacking campaigns targeting Next.JS applications. 🌐URL: https://tlpblack.net/blog/20251209-the-anatomy-of-a-react2shell-compromise 🔎OnVT: https://www.virustotal.com/gui/file/ba43e447e63611d365300bf2e8e43ccb02ea112778d0d555ef9a9ccf6169808b

    Post summary

    The post confirms that CVE-2025-55182 is being actively exploited for cryptojacking against Next.JS applications, but no exploit code or patch is provided.

    2402473.0K
    4.2K followersView on X
  • Marcel Velica@MarcelVelica
    Active Exploitation

    900+ companies hacked. One vulnerability. One automated pipeline. Hackers are using AI + Telegram bots to exploit React2Shell (CVE-2025-55182) at scale stealing credentials, cloud access, and financial data in minutes. This isn’t random hacking. It’s organized, automated, and fast. If you’re not patching in real time, you’re already behind. Are you confident your systems would survive this attack? #CyberSecurity #Infosec #AI #DataBreach

    Post summary

    The message claims CVE‑2025‑55182 is being actively exploited by attackers using AI‑driven Telegram bots, compromising over 900 companies and underscoring the urgency of real‑time patching.

    22028237.3K
    23.0K followersView on X
  • yousukezan@yousukezan
    Exploit

    【React2Shell】CVE-2025-55182 — あなたのNext.jsは今も狙われている https://qiita.com/barshige-sec/items/d49f595c7b646d60aed3 #Qiita @barshigeより

    Post summary

    The post reports on CVE-2025-55182 in Next.js, presents a working React2Shell PoC, claims the vulnerability is still actively exploited, and offers no patch or mitigation details.

    01019102.2K
    12.1K followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - Jenderal92/CVE-2025-55182-React2shell: CVE-2025-55182 Exploit Tool – Python 2.7 exploit for Next.js prototype pollution leading to RCE · GitHub https://github.com/Jenderal92/CVE-2025-55182-React2shell

    Post summary

    The GitHub repository hosts a Python 2.7 exploit for Next.js prototype pollution (CVE-2025-55182) that leads to remote code execution, providing functional exploitation code but no evidence of active attacks or patches.

    0501682.0K
    62.5K followersView on X
CPE platform detail76 entries

76 of 76 entries

PartVendorProductVersionTarget SWTarget HW
Appfacebookreact19.0.0--
Appfacebookreact19.1.0--
Appfacebookreact19.1.1--
Appfacebookreact19.2.0--
Appvercelnext.js-node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js14.3.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js16.0.0node.js-

Explore more