2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web services at risk. On December 3, React disclosed CVE-2025-55182, a critical flaw in React Server Components with a CVSS score of 10. The vulnerability stems from insecure deserialization within the “Flight” protocol used by React […]

The post 2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: