Vulnerabilities · 120 days ago

React Server Components Face Hour-Scale Ransomware Risk

React Server Components is no longer a patch-and-test item on a normal cycle. The gap between disclosure and exploitation has collapsed to hours, so a pre-auth RCE can become an active ransomware foothold before weekly validation ever runs.

Synack’s 2026 report says AI-driven scanning cut mean time to remediation by about 47% in 2025 and that public CVEs rose to 48,244. It also ties CVE-2025-55182 to unauthenticated server-side RCE and notes confirmed ransomware use; the affected versions are 19.0.0, 19.1.0, 19.1.1, and 19.2.0.

The operational shift matters as much as the bug itself. Periodic testing misses hour-scale abuse, and internet-exposed React/Next.js services now need to be treated as immediate initial-access candidates, not routine application-risk items.

CVE-2025-55182

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Dec 12 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-19

Editions

Related stories