Back to blog

Blog Post

New offensive security research: Remote Code Execution (RCE) vulnerability in Next.js

Share on social

Jan 17, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
New offensive security research: Remote Code Execution (RCE) vulnerability in Next.js

[RCE Vulnerability Research]

To support customer testing and validation, we've added a reverse-engineered proof of concept to Assetnote. Our research team also published an open-source test, which is available on our GitHub.

Contact sales

An advisory has revealed a critical, unauthenticated Remote Code Execution (RCE) vulnerability in Next.js, rooted in React Server Components, which requires immediate patching. Given the severity of this issue, in addition to developing a high-fidelity check across our ASM platform, Assetnote, our Security Research team also published an open-source command-line tool for detecting CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server components.

Communicating the critical risk: Executive summary

Next.js is a powerful web development framework that simplifies the process of building fast, interactive applications. If a bad actor was able to exploit this RCE vulnerability, they could take full control of your app, access and exfiltrate data, or use their access as a way to pivot into other systems and conduct disruptive attacks.

Searchlight Cyber's security research team constantly uncovers new vulnerabilities and feeds them directly into our platform, giving you early warnings on zero-days so you can mitigate them before attackers have the chance to exploit them.

Read the full advisory on our security research blog

About Assetnote

Searchlight Cyber's ASM solution, Assetnote, provides industry-leading attack surface management and adversarial exposure validation solutions, helping organizations identify and remediate security vulnerabilities before they can be exploited. Customers receive security alerts and recommended mitigations simultaneously with any disclosures made to third-party vendors. Visit our attack surface management page to learn more about our platform and the research we do.

Alex Blackman

Author

Alex Blackman

Head of Product Marketing at Searchlight Cyber

Alex Blackman leads product marketing at Searchlight Cyber, where he's responsible for taking the company's Preemptive Threat Exposure Management platform to market. Before joining Searchlight, Alex worked with global brands including Unilever and Allianz. He runs Searchlight's webinar programme and spends most of his time helping security teams understand why preemptive beats reactive and how that works in the Searchlight platform.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient