logo

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

ID: bc75cce7-245d-518e-83e0-facc788bd6f6

STIX ID: report--bc75cce7-245d-518e-83e0-facc788bd6f6

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: [email protected] (The Hacker News)

...
...

Alert: CVE-2026-16723 is a critical remote-code-execution flaw in Fastjson 1.2.68–1.2.83 that can be exploited against Spring Boot executable fat-JARs by sending crafted JSON; no AutoType or classpath gadget is required. ThreatBook and Imperva reported observed exploit activity against multiple industries, Alibaba and researchers provided technical analysis and mitigations (enable -Dfastjson.parser.safeMode=true or migrate to Fastjson2), and organizations are urged to inventory Fastjson dependencies and look for indicators like nested @type values, unexpected outbound fetches, and web shells.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.