Hackers target US firms in FastJson RCE zero-day attacks
Reported exploitedFastjson 1.xOur summary
A critical zero-day vulnerability in Alibaba's FastJson library is being actively exploited against U.S.-based companies, enabling remote code execution without user interaction or elevated privileges. The flaw, tracked as CVE-2026-16723, impacts versions 1.2.68 through 1.2.83 and has been observed in attacks spanning multiple industries including finance, healthcare, and retail. Security researchers have confirmed global targeting, with incidents reported in Singapore and Canada as well. Alibaba warns that no official fix is planned for the outdated 1.x branch, urging users to switch to safe deployment models or upgrade to fastjson2.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.