Hackers target US firms in FastJson RCE zero-day attacks
ID: 6bdb195a-3019-59e8-a464-e30905487650
STIX ID: report--6bdb195a-3019-59e8-a464-e30905487650
Feed Name: Bleeping Computer
FastJson RCE zero-day (CVE-2026-16723) is being actively exploited in the wild against primarily US-based organizations across multiple industries. The flaw in FastJson 1.2.68–1.2.83 allows remote code execution via attacker-controlled type-resolution during deserialization in Spring Boot fat-JAR deployments, requires no user interaction or elevated privileges, and currently has no available patch for affected 1.x releases; vendors recommend enabling SafeMode or migrating to non-impacted builds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
