A critical vulnerability in React Server Components (CVE-2025-55182) and Next.js (CVE-2025-66478) allows unauthenticated attackers to execute remote code through insecure deserialization. Payload recommends upgrading React to 19.2.3 and Next.js to 15.4.10 immediately.