
12/11/2025 · Cloudforce One
What this post added
This post details the immediate response to the React2Shell vulnerability (CVE-2025-55182) and two related RSC vulnerabilities (CVE-2025-55183, CVE-2025-55184). It describes the threat actor tactics and techniques observed during early exploitation, including the use of vulnerability intelligence, reconnaissance tools, and specific scanning methods. Cloudflare has deployed new WAF rules to block exploitation and scanning attempts for these vulnerabilities, providing specific rule IDs for both free and paid customers.