Vulnerabilità ed exploit

React Server Components Affronta un Rischio Ransomware su Scala Oraria

React Server Components non è più un elemento da patch-and-test su un ciclo normale. Il divario tra disclosure e exploitation si è ridotto a poche ore, quindi un RCE pre-auth può diventare un foothold ransomware attivo prima ancora che venga eseguita la convalida settimanale.

1 fonte · 18 mag

CVE-2025-55182

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0… Impiego noto in campagne ransomware. EPSS 100% (100º percentile).

Data di correzione federale CISA 12 dic · data superata

Cronologia

Fonti

Part of the PlainSec briefing for 2026-05-18

Every edition of this story: React Server Components Affronta un Rischio Ransomware su Scala Oraria

Altro da oggi