Exploitation timeline
Threadlinqs has recorded 5 Vercel CVEs published between and . The busiest month was 2025-12 (4 new CVEs). 1 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Vercel CVEs.
- CVE-2025-55182critical 10KEVRansomwareEPSS 84.9%
- CVE-2025-29927critical 9.1EPSS 92.1%
- CVE-2025-55184high 7.5EPSS 21.1%
- CVE-2025-55183medium 5.3EPSS 21%
- CVE-2025-67779high 7.5EPSS 0.2%
Products affected
Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 1 distinct Vercel product is affected. The most frequently affected:
- Next.js 5 CVEs
Threat activity
25 tracked threat campaigns reference Vercel products or exploit Vercel CVEs:
- Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty AwardedHIGH
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio BreachesHIGH
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB CredentialsHIGH
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate ProgramCRITICAL
- Fake IT Support Calls on Microsoft Teams Push EtherRAT — Node.js RAT Using EtherHiding (Ethereum Smart Contract C2), Linked to React2Shell (CVE-2025-55182) Exploitation ChainHIGH
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt StrikeHIGH
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark CampaignHIGH
- AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc Bytecode, Archive Indirection & Prompt Injection (Trail of Bits)HIGH
- SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon CVE-2021-26855/26857/26858/27065) and IIS to Deploy GODZILLA Web Shells and ShadowPadHIGH
- PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)CRITICAL
- Lazarus Group (DPRK) Hides BeaverTail / InvisibleFerret Loader in Git Hooks via precommit.vercel.app — Contagious Interview / TaskJacker Evolution (May 2026)HIGH
- AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000 Compromised Accounts)HIGH
- Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and CVE-2025-9501 (W3 Total Cache)CRITICAL
- Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)HIGH
- Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub TokensHIGH
- Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable ExposureHIGH
- Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat ActorsCRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 PayloadCRITICAL
- EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious InterviewCRITICAL
- TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain AttacksCRITICAL
- React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0)CRITICAL
Threat actors targeting Vercel
Named threat actors attributed to campaigns that involve Vercel products or CVEs, with the number of linked campaigns:
How to prioritise Vercel patching
This order follows the data Threadlinqs holds for Vercel, not a generic severity checklist:
- 1 of 5 Vercel CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2025-55182.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2025-29927 (92.1%), CVE-2025-55184 (21.1%), CVE-2025-55183 (21%).
- 2 CVEs score Critical and 2 High on CVSS v3 (maximum 10, average 7.9); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.