# Vercel vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 5 Vercel CVEs, 1 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 25 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 Vercel CVEs published between 2025-03-15 and 2025-12-15. The busiest month was 2025-12 (4 new CVEs). 1 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Vercel CVEs.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182) — CRITICAL 10 · KEV · Ransomware · EPSS 84.9% · 2025-12-03
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927) — CRITICAL 9.1 · EPSS 92.1% · 2025-03-21
- [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184) — HIGH 7.5 · EPSS 21.1% · 2025-12-11
- [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183) — MEDIUM 5.3 · EPSS 21% · 2025-12-11
- [CVE-2025-67779](https://intel.threadlinqs.com/cve/CVE-2025-67779) — HIGH 7.5 · EPSS 0.2% · 2025-12-12

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 1 distinct Vercel product is affected. The most frequently affected:

- Next.js — 5 CVEs

## Threat activity

25 tracked threat campaigns reference Vercel products or exploit Vercel CVEs:

- [Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded](https://intel.threadlinqs.com/threat/TL-2026-2878) — HIGH — 2026-10-04
- [OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches](https://intel.threadlinqs.com/threat/TL-2026-2018) — HIGH — 2026-08-14
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH — 2026-07-14
- [FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB Credentials](https://intel.threadlinqs.com/threat/TL-2026-1209) — HIGH — 2026-07-11
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program](https://intel.threadlinqs.com/threat/TL-2026-1138) — CRITICAL — 2026-07-06
- [Fake IT Support Calls on Microsoft Teams Push EtherRAT — Node.js RAT Using EtherHiding (Ethereum Smart Contract C2), Linked to React2Shell (CVE-2025-55182) Exploitation Chain](https://intel.threadlinqs.com/threat/TL-2026-1141) — HIGH — 2026-07-06
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — HIGH — 2026-07-03
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — 2026-07-02
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2](https://intel.threadlinqs.com/threat/TL-2026-1088) — HIGH — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — 2026-07-01
- [SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaign](https://intel.threadlinqs.com/threat/TL-2026-0961) — HIGH — 2026-06-27
- [AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc Bytecode, Archive Indirection & Prompt Injection (Trail of Bits)](https://intel.threadlinqs.com/threat/TL-2026-0702) — HIGH — 2026-06-07
- [SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon CVE-2021-26855/26857/26858/27065) and IIS to Deploy GODZILLA Web Shells and ShadowPad](https://intel.threadlinqs.com/threat/TL-2026-0493) — HIGH — 2026-05-11
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)](https://intel.threadlinqs.com/threat/TL-2026-0478) — CRITICAL — 2026-05-07
- [Lazarus Group (DPRK) Hides BeaverTail / InvisibleFerret Loader in Git Hooks via precommit.vercel.app — Contagious Interview / TaskJacker Evolution (May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0464) — HIGH — 2026-05-06
- [AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000 Compromised Accounts)](https://intel.threadlinqs.com/threat/TL-2026-0453) — HIGH — 2026-05-04
- [Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and CVE-2025-9501 (W3 Total Cache)](https://intel.threadlinqs.com/threat/TL-2026-0428) — CRITICAL — 2026-04-27
- [Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)](https://intel.threadlinqs.com/threat/TL-2026-0411) — HIGH — 2026-04-22
- [Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub Tokens](https://intel.threadlinqs.com/threat/TL-2026-0400) — HIGH — 2026-04-21
- [Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable Exposure](https://intel.threadlinqs.com/threat/TL-2026-0394) — HIGH — 2026-04-20
- [Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-0327) — CRITICAL — 2026-04-06
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — CRITICAL — 2026-03-31
- [EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interview](https://intel.threadlinqs.com/threat/TL-2026-0293) — CRITICAL — 2026-03-27
- [TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-0288) — CRITICAL — 2026-03-26
- [React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-0080) — CRITICAL — 2026-02-13

## Threat actors targeting Vercel

Named threat actors attributed to campaigns that involve Vercel products or CVEs, with the number of linked campaigns:

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3 campaigns
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 2 campaigns
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 2 campaigns
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2 campaigns
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1 campaign
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1 campaign
- [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia) — 1 campaign
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1 campaign
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1 campaign
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1 campaign
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 1 campaign
- [Slow Pisces](https://intel.threadlinqs.com/actor/Slow%20Pisces) — 1 campaign

## How to prioritise Vercel patching

This order follows the data Threadlinqs holds for Vercel, not a generic severity checklist:

- 1 of 5 Vercel CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927) (92.1%), [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184) (21.1%), [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183) (21%).
- 2 CVEs score Critical and 2 High on CVSS v3 (maximum 10, average 7.9); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/vercel
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
