CVE Tools

A JSON RCE bug is about to rock the Java world

Risky Business NewsBy Catalin Cimpanu

Reported exploitedFastjsonJava applications

Our summary

A critical vulnerability in Alibaba's Fastjson library, CVE-2026-16723, is being actively exploited to perform unauthenticated remote code execution attacks. The flaw affects the widely used 1.x branch of Fastjson, particularly when deployed as part of Spring Boot applications. Threat actors have already targeted multiple industries, including finance and healthcare, with a focus on U.S.-based organizations. While no official patch has been issued, Alibaba recommends switching to the safer 2.x branch or activating SafeMode in existing deployments.

Read at Risky Business News

Risky Business News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store