Critical vulnerabilities announced in React and Next.js, being actively exploited: CVE-2025-66478 (Next.js) and CVE-2025-55182 (React)
Unauthenticated remote code execution is pretty much as bad as it gets. If you are responsible for a host with a) react-server-dom*: 19.0.0, 19.1.0, 19.1.1, and 19.2.0 or b) Next.js: 14.3.0-canary, 15.x, and 16.x (App Router) patch them ASAP.

