React2Shell (CVE-2025-55182) mass scanning and exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnerability has been used in multiple live campaigns, including Huntress-observed malware delivery, a December 5 ransomware intrusion that deployed Weaxor in under a minute, and a Cisco Talos-tracked credential theft operation tied to UAT-10608. Researchers also reported ILovePoop scans of tens of millions of IP addresses worldwide for exposed React systems, with targeting that included government, defense, finance, and industrial organizations. The activity shows a broad and ongoing exploitation wave across React and Next.js deployments.
Cases
Related Happenings
Major web servers HTTP/2 Bomb remote DoS denial-of-service flaw
Vulnerability
H score39
First: 03.06.2026 11:33
Last: 03.06.2026 11:33
Sources 1
About this happening:
Researchers disclosed HTTP/2 Bomb, a remote denial-of-service vulnerability in default HTTP/2 configurations that can make NGINX, Apache HTTPD, Microsoft IIS, Envoy,...
Major web servers HTTP/2 Bomb remote DoS denial-of-service flaw
VulnerabilityAbout this happening: Researchers disclosed HTTP/2 Bomb, a remote denial-of-service vulnerability in default HTTP/2 configurations that can make NGINX, Apache HTTPD, Microsoft IIS, Envoy,...
Burst Statistics authentication bypass (CVE-2026-8181)
Vulnerability
H score78
First: 15.05.2026 00:07
Last: 15.05.2026 00:07
Sources 1
About this happening:
Burst Statistics on WordPress sites is facing active exploitation of CVE-2026-8181, a critical authentication bypass that can let unauthenticated attackers imperso...
Burst Statistics authentication bypass (CVE-2026-8181)
VulnerabilityAbout this happening: Burst Statistics on WordPress sites is facing active exploitation of CVE-2026-8181, a critical authentication bypass that can let unauthenticated attackers imperso...
FamousSparrow multi-wave intrusion campaign against Azerbaijani oil and gas company
Campaign
H score39
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
A China-affiliated actor tracked as FamousSparrow (UAT-9244) ran a multi-wave intrusion against an unnamed Azerbaijani oil and gas company from late December 202...
FamousSparrow multi-wave intrusion campaign against Azerbaijani oil and gas company
CampaignAbout this happening: A China-affiliated actor tracked as FamousSparrow (UAT-9244) ran a multi-wave intrusion against an unnamed Azerbaijani oil and gas company from late December 202...
MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)
Vulnerability
H score53
First: 05.05.2026 14:56
Last: 05.05.2026 14:56
Sources 1
About this happening:
CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...
MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)
VulnerabilityAbout this happening: CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation Wave
H score89
First: 04.05.2026 11:25
Last: 04.05.2026 11:25
Sources 1
About this happening:
Active exploitation of CVE-2026-41940 is driving a large cPanel & WHM compromise wave, putting exposed servers at risk of administrative takeover. More than 40,000 serve...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation WaveAbout this happening: Active exploitation of CVE-2026-41940 is driving a large cPanel & WHM compromise wave, putting exposed servers at risk of administrative takeover. More than 40,000 serve...
Timeline
-
20.02.2026 23:07 4 articles · 4mo ago
React2Shell scanning and targeting expand worldwide
Campaign Scope UpdateAn unknown, possibly state-sponsored threat actor uses the ILovePoop toolkit to probe tens of millions of IP addresses worldwide for exposed React systems, with targeting that includes government, defense, finance, and industrial organizations, while researchers assess the actor may be involved in state-sponsored espionage and note that React2Shell has also appeared in ransomware campaigns and other botnet activity.
Show sources
- Attackers Use New Tool to Scan for React2Shell Exposure — www.darkreading.com — 20.02.2026 23:07
- Attackers Use New Tool to Scan for React2Shell Exposure — www.darkreading.com — 20.02.2026 23:07
- Automated Credential Harvesting Campaign Exploits React2Shell Flaw — www.darkreading.com — 06.04.2026 18:31
- React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors — thehackernews.com — 10.12.2025 22:19
-
17.12.2025 18:09 1 articles · 7mo ago
React2Shell exploitation deploys Weaxor ransomware
Technical Analysis UpdateOn December 5, 2025, a threat actor exploited CVE-2025-55182 against a React/Next.js-based system at the affected organization, gained initial access, and deployed Weaxor ransomware less than a minute later. The attacker then executed an obfuscated PowerShell command to launch a Cobalt Strike beacon, disabled Windows Defender real-time protection, wiped volume shadow copies, cleared event logs, and left files with the .WEAX extension alongside RECOVERY INFORMATION.txt ransom notes.
Show sources
- Critical React2Shell flaw exploited in ransomware attacks — www.bleepingcomputer.com — 17.12.2025 18:09
-
03.12.2025 02:00 1 articles · 7mo ago
React2Shell is publicly disclosed
Initial DisclosureCVE-2025-55182, also known as React2Shell, is publicly disclosed as a remote code execution vulnerability in React Server Components that can let an attacker take full control of vulnerable web servers with a single web request, sometimes without authentication, and it is rated 10 out of 10 in CVSS.
Show sources
- Attackers Use New Tool to Scan for React2Shell Exposure — www.darkreading.com — 20.02.2026 23:07