Find notable cyber news and cases, enriched with sources, timelines, and signals.

React2Shell (CVE-2025-55182) mass scanning and exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 89
3 unique sources, 4 articles

Summary

Hide ▲

CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnerability has been used in multiple live campaigns, including Huntress-observed malware delivery, a December 5 ransomware intrusion that deployed Weaxor in under a minute, and a Cisco Talos-tracked credential theft operation tied to UAT-10608. Researchers also reported ILovePoop scans of tens of millions of IP addresses worldwide for exposed React systems, with targeting that included government, defense, finance, and industrial organizations. The activity shows a broad and ongoing exploitation wave across React and Next.js deployments.

Cases

Related Happenings

Major web servers HTTP/2 Bomb remote DoS denial-of-service flaw

Vulnerability
H score39 First: 03.06.2026 11:33 Last: 03.06.2026 11:33 Sources 1

About this happening: Researchers disclosed HTTP/2 Bomb, a remote denial-of-service vulnerability in default HTTP/2 configurations that can make NGINX, Apache HTTPD, Microsoft IIS, Envoy,...

Burst Statistics authentication bypass (CVE-2026-8181)

Vulnerability
H score78 First: 15.05.2026 00:07 Last: 15.05.2026 00:07 Sources 1

About this happening: Burst Statistics on WordPress sites is facing active exploitation of CVE-2026-8181, a critical authentication bypass that can let unauthenticated attackers imperso...

FamousSparrow multi-wave intrusion campaign against Azerbaijani oil and gas company

Campaign
H score39 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: A China-affiliated actor tracked as FamousSparrow (UAT-9244) ran a multi-wave intrusion against an unnamed Azerbaijani oil and gas company from late December 202...

MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)

Vulnerability
H score53 First: 05.05.2026 14:56 Last: 05.05.2026 14:56 Sources 1

About this happening: CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: Active exploitation of CVE-2026-41940 is driving a large cPanel & WHM compromise wave, putting exposed servers at risk of administrative takeover. More than 40,000 serve...

Timeline

  1. 20.02.2026 23:07 4 articles · 4mo ago

    React2Shell scanning and targeting expand worldwide

    Campaign Scope Update

    An unknown, possibly state-sponsored threat actor uses the ILovePoop toolkit to probe tens of millions of IP addresses worldwide for exposed React systems, with targeting that includes government, defense, finance, and industrial organizations, while researchers assess the actor may be involved in state-sponsored espionage and note that React2Shell has also appeared in ransomware campaigns and other botnet activity.

    Show sources
  2. 17.12.2025 18:09 1 articles · 7mo ago

    React2Shell exploitation deploys Weaxor ransomware

    Technical Analysis Update

    On December 5, 2025, a threat actor exploited CVE-2025-55182 against a React/Next.js-based system at the affected organization, gained initial access, and deployed Weaxor ransomware less than a minute later. The attacker then executed an obfuscated PowerShell command to launch a Cobalt Strike beacon, disabled Windows Defender real-time protection, wiped volume shadow copies, cleared event logs, and left files with the .WEAX extension alongside RECOVERY INFORMATION.txt ransom notes.

    Show sources
  3. 03.12.2025 02:00 1 articles · 7mo ago

    React2Shell is publicly disclosed

    Initial Disclosure

    CVE-2025-55182, also known as React2Shell, is publicly disclosed as a remote code execution vulnerability in React Server Components that can let an attacker take full control of vulnerable web servers with a single web request, sometimes without authentication, and it is rated 10 out of 10 in CVSS.

    Show sources