MIRAGE
Threat IntelligenceCVEs › CVE-2021-26855

CVE-2021-26855 — exploited in the wild

Defending against the CVE-2025-55182 (React2Shell) vulnerability in React Server Components

Observed by OffSeq honeypot sensors · last 7 days · last seen 2026-08-31

471
Exploitation attempts
57
Attacker networks
436
Sessions
KEV
CISA Known-Exploited

About CVE-2021-26855

CVE-2025-55182, also known as React2Shell, is a critical pre-authentication remote code execution vulnerability affecting React Server Components and related frameworks. With a CVSS score of 10.0, it allows attackers to execute arbitrary code on vulnerable servers through a single malicious HTTP request. Exploitation has been detected since December 5, 2025, primarily in red team assessments but also in real-world attacks delivering coin miners. The vulnerability stems from a failure to validate incoming payloads in React Server Components, enabling attackers to inject malicious structures leading to prototype pollution and remote code execution. Post-exploitation activities include running reverse shells, achieving persistence, evading security defenses, and attempting lateral movement to cloud resources.

OffSeq's global honeypot fleet recorded 471 exploitation attempts against CVE-2021-26855 from 57 distinct attacker networks in the last 7 days. This is direct in-the-wild telemetry — every hit is a real attacker probing a decoy, not a scan of a vulnerability database.

Top attacking countries

Top attacking networks

Techniques observed

Sample request paths

/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool

Open the live CVE-2021-26855 view →

References