CVE Tools

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker NewsBy The Hacker News

Reported exploitedFastjsonJava libraries

Our summary

Attackers are actively exploiting a critical remote code execution (RCE) vulnerability in Fastjson, Alibaba's widely used Java JSON library. Tracked as CVE-2026-16723, this flaw affects versions 1.2.68 through 1.2.83 and enables unauthenticated attackers to execute arbitrary code under certain conditions involving Spring Boot applications. As of July 25, no official patch for the 1.x branch has been released, leaving users vulnerable unless they apply mitigations like enabling SafeMode or upgrading to Fastjson2.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store