CVE Tools

RCE-уязвимость в Fastjson используется в атаках

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedFastjson

Our summary

Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the popular Java library Fastjson, identified as CVE-2026-16723. This flaw allows unauthenticated attackers to execute arbitrary code remotely without user interaction. The issue affects Fastjson versions 1.2.68 through 1.2.83 when used in Spring Boot applications packaged as executable fat JARs. Attackers can exploit this by sending malicious JSON payloads that trigger class loading from external sources, bypassing standard AutoType restrictions. Alibaba has released version 1.2.84 to address the problem, and users are advised to update immediately or enable SafeMode as a temporary mitigation.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store