← Incident database

react2shell-2025 · Disclosed 2025-12-15

React2Shell: exploitation after disclosure

Microsoft reported hundreds of machines compromised through unauthenticated RSC code execution. The vulnerability and fixes were disclosed on December 3.

Known vulnerabilityImplementationCVE-2025-55182

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Microsoft observed compromised devices across organizations; successful exploitation also included red-team assessments.

    [s1]Analyzing CVE-2025-55182 exploitation activity
  • Reported fact

    React disclosed the vulnerability and fixes on December 3.

    [s2]Critical Security Vulnerability

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Microsoft recommends patching, exposure checks, compromise investigation, and rotation of affected secrets.

    [s1]Mitigation and protection guidance

Evidence relevant to prevention

Patch available beforehand

Compare deployed RSC and framework versions with current advisories; inspect compromise traces and credential use after patching.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

This is a campaign record; individual intrusion dates and reasons for delayed patching are unknown.

Sources

  1. [s1] Microsoft · Primary source

    Defending against CVE-2025-55182 (React2Shell) ↗

    Published 2025-12-15 · Reviewed 2026-10-02

  2. [s2] React · Primary source

    Critical Security Vulnerability in React Server Components ↗

    Published 2025-12-03 · Reviewed 2026-10-02