logo

FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public

ID: d9b66d35-b542-5adf-991e-e5507b3691f8

STIX ID: report--d9b66d35-b542-5adf-991e-e5507b3691f8

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: Do Son

...
...

**CVE-2026-16723 — FastJson RCE (CVSS 9.0):** A critical remote code execution flaw in Alibaba FastJson 1.2.68–1.2.83 allows unauthenticated attackers to achieve code execution via crafted @type JSON and nested JAR URL handling; public proof-of-concept code is available and Imperva reports active exploitation across multiple industries. Mitigations include enabling FastJson SafeMode, using noneautotype builds, inventorying/transitive dependencies, and migrating to FastJson 2.x.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.