Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
GorgonAgora: 4,800+ fake storefronts skim cards across hundreds of impersonated brandsSansec (Magento / e-commerce security)·Jun 3, 19:37 UTC · Jun 3, 2026Vulnerability55
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
React2Shell under attack: RondoDox Botnet spreads miners and malwareSecurity Affairs·Jan 1, 14:31 UTC · Jan 1, 2026MalwareCVE-2025-55182CVE-2024-3721CVE-2024-1285660
Atlassian fixed maximum severity flaw CVE-2025Security Affairs·Dec 15, 15:03 UTC · Dec 15, 2025Exploit / PoCCVE-2025-66516CVE-2025-54988CVE-2021-39227+1 CVEs60
New React RSC Vulnerabilities Enable DoS and Source Code ExposureThe Hacker News·Dec 12, 18:36 UTC · Dec 12, 2025VulnerabilityCVE-2025-55182CVE-2025-55184CVE-2025-67779+1 CVEs60
Attacks on Kaspersky honeypots exploit CVE-2025Kaspersky Securelist·Dec 11, 07:30 UTC · Dec 11, 2025Exploit / PoC in the wildCVE-2025-5518260
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple SectorsThe Hacker News·Dec 11, 04:19 UTC · Dec 11, 2025MalwareCVE-2025-5518260
New EtherRAT backdoor surfaces in React2Shell attacks tied to North KoreaSecurity Affairs·Dec 10, 14:45 UTC · Dec 10, 2025MalwareCVE-2025-5518260
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182)Help Net Security·Dec 4, 00:00 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Chinese Hackers Targeting South American Diplomatic Entities with ShadowPadThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2023VulnerabilityCVE-2022-2946460