react2shell-2025 · Disclosed 2025-12-15
React2Shell: exploitation after disclosure
Microsoft reported hundreds of machines compromised through unauthenticated RSC code execution. The vulnerability and fixes were disclosed on December 3.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Microsoft recommends patching, exposure checks, compromise investigation, and rotation of affected secrets.
[s1]Mitigation and protection guidance
Evidence relevant to prevention
Patch available beforehand
Compare deployed RSC and framework versions with current advisories; inspect compromise traces and credential use after patching.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
This is a campaign record; individual intrusion dates and reasons for delayed patching are unknown.
Sources
[s1] Microsoft · Primary source
Defending against CVE-2025-55182 (React2Shell) ↗Published 2025-12-15 · Reviewed 2026-10-02
[s2] React · Primary source
Critical Security Vulnerability in React Server Components ↗Published 2025-12-03 · Reviewed 2026-10-02