Website Security & Threat Management
React2Shell and related RSC vulnerabilities threat brief- early exploitation activity and threat actor techniques

React2Shell and related RSC vulnerabilities threat brief- early exploitation activity and threat actor techniques

12/11/2025 · Cloudforce One

What this post added

This post details the immediate response to the React2Shell vulnerability (CVE-2025-55182) and two related RSC vulnerabilities (CVE-2025-55183, CVE-2025-55184). It describes the threat actor tactics and techniques observed during early exploitation, including the use of vulnerability intelligence, reconnaissance tools, and specific scanning methods. Cloudflare has deployed new WAF rules to block exploitation and scanning attempts for these vulnerabilities, providing specific rule IDs for both free and paid customers.

Read the original post ↗