Critical RCE Vulnerability in fastjson Disclosed (CVE-2026-16723)
ID: 5374faa8-f15b-5228-8594-ec952ee0d71b
STIX ID: report--5374faa8-f15b-5228-8594-ec952ee0d71b
Feed Name: ThreatCluster
Threat Score
A critical remote code execution vulnerability (CVE-2026-16723) was disclosed in fastjson versions 1.2.68–1.2.83; the flaw permits unauthenticated attackers to execute arbitrary code over the network without requiring AutoType or classpath gadgets (CVSS 9.0). No public proof-of-concept or confirmed exploitation has been reported; immediate mitigation recommended is upgrading fastjson beyond 1.2.83 and restricting network access to vulnerable applications (published July 23, 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
