New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers

A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in Next.js and React frameworks. The malware targets Next.js deployments by exploiting two critical vulnerabilities, CVE-2025-29927 and CVE-2025-66478, which allow remote code execution without authentication. The attack uses prototype pollution and command […]

The post New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: