Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Short answer: React2Shell exploitation is still being reported. A September 29, 2026 advisory describes attackers using CVE-2025-55182 to deliver ZnDoor, but the available evidence does not establish that exploitation volume is increasing across the internet. If you run an affected React Server Components or Next.js release, upgrade to the branch-specific fixed version immediately; a WAF is only a supplementary control.
What “continued exploitation” means
React2Shell is CVE-2025-55182, a critical unauthenticated remote-code-execution vulnerability in React Server Components. It was publicly disclosed on December 3, 2025. “Unauthenticated” means an attacker does not need a valid application account before attempting exploitation.
The latest dated signal in the available reporting is a September 29, 2026 Nigeria CSIRT advisory, which reports continued exploitation to deliver ZnDoor, described there as a remote-access trojan. That is evidence that exploitation was still occurring at that time, not proof of an ecosystem-wide rise.
Claims that activity is “ramping up” require a defined metric, observation period and comparable baseline. Scanning, exploit attempts, blocked requests and confirmed compromises measure different things and cannot be combined into one trend line.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Which React and Next.js versions are affected?
Use the live Next.js security advisory to confirm the release for your branch. The advisory identifies these affected React Server Components packages and fixes:
| Package | Affected releases | Fixed releases |
|---|---|---|
react-server-dom-webpack |
19.0.0, 19.1.0, 19.1.1 and 19.2.0 | 19.0.1, 19.1.2 and 19.2.1 |
react-server-dom-parcel |
19.0.0, 19.1.0, 19.1.1 and 19.2.0 | 19.0.1, 19.1.2 and 19.2.1 |
react-server-dom-turbopack |
19.0.0, 19.1.0, 19.1.1 and 19.2.0 | 19.0.1, 19.1.2 and 19.2.1 |
For Next.js, the affected applications are 15.x and 16.x projects using the App Router. The advisory also includes experimental 14.3.0-canary.77 and later builds in that canary line. The branch-specific fixed releases listed by the advisory are:
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
| Next.js branch | Fixed release |
|---|---|
| 15.0.x | 15.0.5 |
| 15.1.x | 15.1.9 |
| 15.2.x | 15.2.6 |
| 15.3.x | 15.3.6 |
| 15.4.x | 15.4.8 |
| 15.5.x | 15.5.7 |
| 16.0.x | 16.0.7 |
| 14.3.0-canary.77 and later in that canary line | Not stated in this summary; follow the canary guidance in the advisory. |
Vercel’s June 29, 2026 security bulletin states that every Next.js 15.0.0 through 16.0.6 deployment is affected and that upgrading is the only complete fix. It also recommends verifying the versions actually deployed for next and all three React Server Components packages, rather than trusting only a source manifest.
What exploitation reports have established
Activity began soon after disclosure
AWS reported exploit attempts within hours of disclosure from infrastructure it associated with China-nexus groups Earth Lamia and Jackpot Panda. AWS also cautioned that shared anonymization infrastructure makes definitive attribution difficult, so this should be described as AWS-attributed infrastructure and activity—not confirmed responsibility for every request. Read the AWS analysis.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Google Threat Intelligence Group reported exploitation across clusters ranging from opportunistic criminal activity to suspected espionage. Its December 2025 reporting named MINOCAT, SNOWLIGHT, HISONIC and COMPOOD payloads, along with XMRIG cryptocurrency miners. Google also warned that some early public proof-of-concept material was nonfunctional or designed to target security researchers, so circulation of a PoC is not validation that it works. See Google’s report.
September 2026 reporting shows persistence
The Nigeria CSIRT listing dated September 29, 2026 reports React2Shell being used to compromise network devices and deliver ZnDoor. It is the most recent dated observation identified here, but one advisory does not provide a global attack count or a comparable earlier measurement.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Why the numbers cannot be merged
Each source observes a different population and event type:
| Source and date | Telemetry or claim | How to interpret it |
|---|---|---|
| Vercel, December 2025 | More than 6 million exploit attempts blocked during the weeks after disclosure; 2.3 million blocked in one peak 24-hour period | Firewall blocks on Vercel’s platform, not successful intrusions or internet-wide totals |
| Vercel, December 2025 | 116 security researchers and 20 unique WAF updates reported within 48 hours | Vercel’s mitigation-program figures, not a count of attackers |
| AWS, December 4, 2025 (updated December 29) | Attempts observed from infrastructure associated with named groups | Infrastructure attribution with the anonymization caveat described by AWS |
| Google, December 2025 | Incident-intelligence observations of multiple payload clusters | Threat-actor and malware reporting, not a rate measurement |
| Singh et al., March 12, 2026 | An active network-telescope study describing rapid post-disclosure scanning | A preprint whose abstract does not establish a precise global attack total; see the paper for method and measurements |
| Nigeria CSIRT, September 29, 2026 | Reported continued ZnDoor exploitation | A recent observation that does not by itself demonstrate rising volume |
The Vercel figures come from Vercel’s December 19, 2025 account. They count blocked requests and mitigation work, not confirmed compromises or unique adversaries.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
How to check whether your deployment is exposed
- Inspect declared dependencies. Review
package.jsonand the lockfile fornext,react-server-dom-webpack,react-server-dom-parcelandreact-server-dom-turbopack. - Resolve the installed tree. Run your package manager’s dependency-list command—for npm,
npm ls next react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack—and record the versions on the production build. - Check the application architecture. Next.js 15.x and 16.x applications using the App Router are in scope; do not assume a project is safe because it also contains Pages Router routes.
- Verify the deployed artifact. Check the image, serverless bundle or hosting dashboard, because a patched local branch does not protect an older artifact that is still serving traffic.
How to patch React2Shell safely
- Select the matching fixed release. Choose the fixed version for your maintained Next.js branch from the table and update the React Server Components packages to 19.0.1, 19.1.2 or 19.2.1 as applicable. Do not jump branches without checking framework compatibility.
- Regenerate and review the lockfile. Install with your normal package manager, commit the resulting lockfile, and confirm that transitive React Server Components packages no longer resolve to an affected release.
- Build and test the production configuration. Exercise App Router server actions, route handlers, streaming responses and authentication flows in a staging environment before promotion.
- Redeploy every exposed instance. Replace old containers, serverless revisions and edge deployments; invalidate caches that could continue routing requests to an unpatched build.
- Confirm the runtime after deployment. Repeat the dependency check against the running artifact and retain the deployment identifier and timestamp for your incident record.
The advisory’s versions can change as branches evolve, so use the linked release guidance rather than treating these numbers as a permanent support matrix.
Does a WAF make patching unnecessary?
No. Vercel says WAF rules cannot guarantee protection against every exploit variant and identifies upgrading as the only complete fix. A WAF can reduce exposure while a release is being prepared, but it should be treated as a compensating control: keep it enabled, monitor blocked and allowed requests, and patch the application itself.
Quick Recap
What to do if exploitation may have occurred
- Preserve web, application, hosting and identity-provider logs before rotating or deleting infrastructure.
- Look for unexpected child processes, modified application files, new startup tasks, outbound connections and unfamiliar administrative accounts.
- Rotate secrets that the application could read, including database credentials, API keys, signing keys and cloud tokens; revoke active sessions where appropriate.
- Rebuild from a known-good source, deploy a fixed dependency set, and remove potentially compromised instances rather than merely restarting them.
- Use the timing of suspicious requests, process creation and outbound traffic to scope whether the event was an exploit attempt or a confirmed compromise.
Practical decision checklist
- Your React Server Components package is on 19.0.0, 19.1.0, 19.1.1 or 19.2.0: upgrade to the corresponding fixed React release.
- Your Next.js App Router deployment is on an affected 15.x or 16.x release: move to the branch-specific fixed version listed above.
- You rely on WAF filtering alone: keep the rule set, but schedule and verify the code upgrade.
- You see suspicious post-disclosure activity: preserve evidence, rotate reachable secrets and redeploy from a clean, patched build.
- You are comparing “ramp-up” claims: require the source, observation window, population and event definition before drawing a trend conclusion.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

