Monday, September 21, 2026

644K+ Websites at Risk Due to Critical React Server Components Flaw

The Shadowserver Foundation has issued an urgent update regarding the critical “React2Shell” vulnerability, identifying a massive attack surface that remains exposed to potential exploitation.

Following targeted improvements to their scanning infrastructure on December 8, 2025, researchers discovered that over 644,000 domains and 165,000 unique IP addresses are still running vulnerable instances of React Server Components.

Understanding the React2Shell Threat

The vulnerability, tracked as CVE-2025-55182, is a critical security flaw affecting React Server Components (RSC).

Security experts have dubbed the flaw “React2Shell” due to its severity and nature. It allows unauthenticated remote attackers to execute arbitrary code on the target server.

The issue stems from insecure deserialization vulnerabilities in the “Flight” protocol that React uses to manage server-client communication.

Because the flaw can be exploited without any user interaction or authentication, it has been assigned the highest possible risk ratings.

Shadowserver’s latest data reveals that despite the initial disclosure of the vulnerability earlier this month, a significant portion of the web remains unpatched.

The foundation collaborated with security partners ValidinLLC and leak_ix to refine their scanning techniques, resulting in a more accurate detection of affected systems.

The discovery of over 644,000 vulnerable domains indicates that many organizations have not yet applied the necessary security updates to their web applications and server environments.

Security teams and administrators are urged to check their systems immediately for compromise.

The widespread nature of this vulnerability makes it a prime target for automated exploitation campaigns, where attackers scan the internet for unpatched servers to install ransomware or steal data.

Organizations using React Server Components should verify their deployments against the latest vendor advisories and apply available patches instantly to close this critical security gap.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools

A newly identified information-stealing campaign, tracked as Rapuncel, is...

BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

A recently published proof-of-concept project named BigDiskBuster claims to...

Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords

Threat actors are increasingly abusing Microsoft Teams' external chat...

New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches

Security researchers have unveiled a cache poisoning technique called...

Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors

North Korea-linked threat actor TraderTraitor has expanded its developer-focused...

HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise

“HEIF Heist,” a broad class of image-processing attack paths...

Related Articles

Recent News