• News/
  • https://www.theregister.com/2025/12/12/vulnerable_react_instances_unpatched/

Half of exposed React servers remain unpatched amid attacks

The Register
·
Carly Page
·
Published Dec 12, 2025
·
Updated

Half of the internet-facing systems vulnerable to a fast-moving React remote code execution flaw remain unpatched, even as exploitation has exploded into more than a dozen active attack clusters ranging from bargain-basement cryptominers to state-linked intrusion tooling. That's the assessment from Alon Schindel, VP of AI and Threat Research at Wiz, who says CVE-2025-55182 – the React server-side vulnerability dubbed "React2Shell" – is now being actively exploited at scale, with researchers tracking at least 15 distinct intrusion clusters in the wild over the past 24 hours alone. According to Wiz's latest telemetry, roughly 50 percent of publicly exposed resources known to be vulnerable are still running unpatched code, giving attackers a comfortable head start. The critical-severity flaw, first disclosed earlier this month, affects React Server Components and dependent frameworks such as Next.js and stems from unsafe deserialization in React's server-side packages, allowing an unauthenticated attacker to send a crafted request to achieve remote code execution. As The Register previously reported, the bug quickly proved attractive to attackers because of React's ubiquity in modern web stacks, particularly in cloud-hosted environments where a single exposed endpoint can provide a foothold into far larger estates. What began as opportunistic scanning and cryptomining has now broadened into something messier. Wiz says it is seeing a clear split between "commodity" exploitation –...

Read full article

Affected Software

2 affected components
Meta React
Vercel Next.js
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the prevalence of unpatched React servers vulnerable to a remote code execution flaw amid ongoing cyberattacks.

2

What security implications are discussed in the article?

The article highlights significant risks posed by active exploitation of the React vulnerability, potentially leading to unauthorized access and system compromise.

3

What software is affected by the vulnerability mentioned in the article?

The vulnerability affects Meta React and Vercel Next.js software.

4

How many exposed React servers are reported to remain unpatched?

The article states that half of the exposed React servers remain unpatched.

5

What types of attacks are associated with this React vulnerability?

The article mentions various attacks, including those involving cryptominers and state-linked intrusion tools.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203