Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

644K+ Websites at Risk Due to Critical React Server Components Flaw

The Shadowserver Foundation has released an update concerning the "React2Shell" vulnerability, highlighting a substantial attack surface that remains susceptible to exploitation.

The Shadowserver Foundation has released an update concerning the "React2Shell" vulnerability, highlighting a substantial attack surface that remains susceptible to exploitation.

Following enhancements to their scanning infrastructure on Mon, Dec 8, 2025, researchers identified over 644,000 domains and 165,000 unique IP addresses still operating vulnerable instances of React Server Components.

The vulnerability, designated as CVE-2025-55182, is a critical security flaw impacting React Server Components (RSC). It allows remote attackers to execute arbitrary code on the target server without authentication.

The flaw arises from insecure deserialization vulnerabilities in the "Flight" protocol used by React for server-client communication. As it can be exploited without user interaction or authentication, it has been assigned the highest risk ratings.

The vulnerability, designated as CVE-2025-55182, is a critical security flaw impacting React Server Components (RSC).
Julia Kramer · Thehackingpost

Despite the initial disclosure earlier this month, a significant portion of the web remains unpatched, according to Shadowserver's latest data.

The foundation, in collaboration with security partners ValidinLLC and leak_ix, refined their scanning techniques, leading to more accurate detection of affected systems. This discovery underscores that numerous organizations have not yet applied necessary security updates to their applications and server environments.

Security teams and administrators are advised to immediately inspect their systems for potential compromise. The widespread nature of this vulnerability makes it an attractive target for automated exploitation campaigns, where unpatched servers may be targeted for ransomware installation or data theft.

Advertisement

Organizations utilizing React Server Components should verify their deployments against the latest vendor advisories and apply available patches promptly to address this security gap.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories