CVE Tools

Unpatched Fastjson Vulnerability Exploited in Attacks

SecurityWeekBy Ionut Arghire

Reported exploitedFastjson 1.x

Our summary

A critical remote code execution vulnerability in Alibaba's Fastjson library, tracked as CVE-2026-16723, is being actively exploited by threat actors. The flaw affects all versions of Fastjson 1.x from 1.2.68 through 1.2.83, which are now unsupported. Attackers can exploit this issue without authentication or user interaction, allowing them to run arbitrary code on vulnerable servers. Security firms like Imperva have detected attacks targeting multiple industries globally, including finance, healthcare, and retail. Organizations are urged to upgrade to Fastjson 2.x or apply mitigations such as enabling SafeMode.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store