React Server Components Face Hour-Scale Ransomware Risk

React Server Components is no longer a patch-and-test item on a normal cycle. The gap between disclosure and exploitation has collapsed to hours, so a pre-auth RCE can become an active ransomware foothold before weekly validation ever runs. Synack’s 2026 report says AI-driven scanning cut mean time to remediation by about 47% in 2025 and that public CVEs rose to 48,244. It also ties CVE-2025-55182 to unauthenticated server-side RCE and notes confirmed ransomware use; the affected versions are 19.0.0, 19.1.0, 19.1.1, and 19.2.0. The operational shift matters as much as the bug itself. Periodic testing misses hour-scale abuse, and internet-exposed React/Next.js services now need to be treated as immediate initial-access candidates, not routine application-risk items.

Part of the PlainSec briefing for 2026-05-19

Sources