FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public
ID: d9b66d35-b542-5adf-991e-e5507b3691f8
STIX ID: report--d9b66d35-b542-5adf-991e-e5507b3691f8
Feed Name: securityonline.info
**CVE-2026-16723 — FastJson RCE (CVSS 9.0):** A critical remote code execution flaw in Alibaba FastJson 1.2.68–1.2.83 allows unauthenticated attackers to achieve code execution via crafted @type JSON and nested JAR URL handling; public proof-of-concept code is available and Imperva reports active exploitation across multiple industries. Mitigations include enabling FastJson SafeMode, using noneautotype builds, inventorying/transitive dependencies, and migrating to FastJson 2.x.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
