Barracuda Application Protection safeguards against critical React and Next.js vulnerabilities
Two critical remote code execution (RCE) vulnerabilities—CVE-2025-55182 and CVE-2025-66478—impact applications built on React and Next.js, enabling attackers to execute arbitrary code without authentication. Barracuda Application Protection, including Barracuda WAF and WAF-as-a-Service, offers automatic safeguards against these threats through real-time signature updates and layered defenses.
Search the blog
The Ransomware Insights Report 2025
Key findings about the experience and impact of ransomware on organizations worldwide
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
Managed Vulnerability Security: Faster remediation, fewer risks, easier compliance
See how easy it can be to find the vulnerabilities cybercriminals want to exploit