logo

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

ID: 169389c4-2603-5060-9450-94d5b53a66ca

STIX ID: report--169389c4-2603-5060-9450-94d5b53a66ca

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-26

Date Updated: 2026-07-26

...
...

**CVE-2026-16723 — Fastjson 1.x RCE in the wild:** A critical, unpatched remote-code-execution flaw in Fastjson 1.2.68–1.2.83 (Spring Boot fat-JAR) enables attacker-controlled bytecode loading via nested jar:// URLs; exploitation was confirmed by ThreatBook and Imperva beginning 2026-07-22, affects major JDKs, bypasses AutoType protections and deserialization blacklists, and has no patch as of 2026-07-26 — organizations should apply SafeMode, WAF/egress controls, audit dependencies, and migrate to Fastjson 2.x immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.