Half of the internet-facing systems vulnerable to a fast-moving React remote code execution flaw remain unpatched, even as exploitation has exploded into more than a dozen active attack clusters ranging from bargain-basement cryptominers to state-linked intrusion tooling. That's the assessment from Alon Schindel, VP of AI and Threat Research at Wiz, who says CVE-2025-55182 – the React server-side vulnerability dubbed "React2Shell" – is now being actively exploited at scale, with researchers tracking at least 15 distinct intrusion clusters in the wild over the past 24 hours alone. According to Wiz's latest telemetry, roughly 50 percent of publicly exposed resources known to be vulnerable are still running unpatched code, giving attackers a comfortable head start. The critical-severity flaw, first disclosed earlier this month, affects React Server Components and dependent frameworks such as Next.js and stems from unsafe deserialization in React's server-side packages, allowing an unauthenticated attacker to send a crafted request to achieve remote code execution. As The Register previously reported, the bug quickly proved attractive to attackers because of React's ubiquity in modern web stacks, particularly in cloud-hosted environments where a single exposed endpoint can provide a foothold into far larger estates. What began as opportunistic scanning and cryptomining has now broadened into something messier. Wiz says it is seeing a clear split between "commodity" exploitation –...
Half of exposed React servers remain unpatched amid attacks
The Register
·Carly Page
·Published Dec 12, 2025
·Updated
Affected Software
2 affected components
Meta React
Vercel Next.js
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the prevalence of unpatched React servers vulnerable to a remote code execution flaw amid ongoing cyberattacks.
2
What security implications are discussed in the article?
The article highlights significant risks posed by active exploitation of the React vulnerability, potentially leading to unauthorized access and system compromise.
3
What software is affected by the vulnerability mentioned in the article?
The vulnerability affects Meta React and Vercel Next.js software.
4
How many exposed React servers are reported to remain unpatched?
The article states that half of the exposed React servers remain unpatched.
5
What types of attacks are associated with this React vulnerability?
The article mentions various attacks, including those involving cryptominers and state-linked intrusion tools.