Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
ID: bc75cce7-245d-518e-83e0-facc788bd6f6
STIX ID: report--bc75cce7-245d-518e-83e0-facc788bd6f6
Feed Name: The Hacker News
Alert: CVE-2026-16723 is a critical remote-code-execution flaw in Fastjson 1.2.68–1.2.83 that can be exploited against Spring Boot executable fat-JARs by sending crafted JSON; no AutoType or classpath gadget is required. ThreatBook and Imperva reported observed exploit activity against multiple industries, Alibaba and researchers provided technical analysis and mitigations (enable -Dfastjson.parser.safeMode=true or migrate to Fastjson2), and organizations are urged to inventory Fastjson dependencies and look for indicators like nested @type values, unexpected outbound fetches, and web shells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
