CVE-2021-26855 — exploited in the wild
Defending against the CVE-2025-55182 (React2Shell) vulnerability in React Server Components
Observed by OffSeq honeypot sensors · last 7 days · last seen 2026-08-31
About CVE-2021-26855
CVE-2025-55182, also known as React2Shell, is a critical pre-authentication remote code execution vulnerability affecting React Server Components and related frameworks. With a CVSS score of 10.0, it allows attackers to execute arbitrary code on vulnerable servers through a single malicious HTTP request. Exploitation has been detected since December 5, 2025, primarily in red team assessments but also in real-world attacks delivering coin miners. The vulnerability stems from a failure to validate incoming payloads in React Server Components, enabling attackers to inject malicious structures leading to prototype pollution and remote code execution. Post-exploitation activities include running reverse shells, achieving persistence, evading security defenses, and attempting lateral movement to cloud resources.
OffSeq's global honeypot fleet recorded 471 exploitation attempts against CVE-2021-26855 from 57 distinct attacker networks in the last 7 days. This is direct in-the-wild telemetry — every hit is a real attacker probing a decoy, not a scan of a vulnerability database.
Top attacking countries
- Germany166
- United States89
- Canada84
- United Kingdom60
- The Netherlands53
- Singapore18
Top attacking networks
Techniques observed
Sample request paths
/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool