Zero-dayApr 10, 2026
React2Shell (CVE-2025-55182) was exploited within 2 days of public disclosure. Attackers executed...
React2Shell (CVE-2025-55182) exploited within 2 days of disclosure to compromise Kubernetes clusters.
Summary
CVE-2025-55182, a React-based vulnerability dubbed React2Shell, was actively exploited by attackers just 2 days after public disclosure. The vulnerability allowed remote code execution in Kubernetes workloads, enabling attackers to install backdoors and exfiltrate data. The exploit demonstrates rapid weaponization of disclosed flaws targeting containerized infrastructure.
Indicators of Compromise
- cve — CVE-2025-55182
Entities
React (product)Kubernetes (technology)React2Shell (campaign)