Hackers target US firms in FastJson RCE zero-day attacks

Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting CVE-2026-16723 in the FastJson open-source Java library to achieve remote code execution without user interaction or elevated privileges. The attacks are primarily hitting U.S.-based organizations across multiple sectors, including financial services, healthcare, retail, and computing. #FastJson #CVE-2026-16723 #ThreatBook #Imperva #Alibaba #FearsOff

Keypoints

  • CVE-2026-16723 is being actively exploited in FastJson 1.2.68 through 1.2.83.
  • The flaw enables remote code execution without user interaction or elevated privileges.
  • Attacks are mostly targeting organizations in the United States.
  • Imperva reported victims across financial services, healthcare, computing, retail, and business sectors.
  • Alibaba has not released a fix, and users are advised to enable SafeMode or move to a non-affected build.

Read More: https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/