logo

Critical RCE Vulnerability in fastjson Disclosed (CVE-2026-16723)

ID: 5374faa8-f15b-5228-8594-ec952ee0d71b

STIX ID: report--5374faa8-f15b-5228-8594-ec952ee0d71b

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

A critical remote code execution vulnerability (CVE-2026-16723) was disclosed in fastjson versions 1.2.68–1.2.83; the flaw permits unauthenticated attackers to execute arbitrary code over the network without requiring AutoType or classpath gadgets (CVSS 9.0). No public proof-of-concept or confirmed exploitation has been reported; immediate mitigation recommended is upgrading fastjson beyond 1.2.83 and restricting network access to vulnerable applications (published July 23, 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.