Threat actors are actively exploiting a critical Fastjson remote code execution flaw, tracked as CVE-2026-16723, affecting widely used Spring Boot fat-jar deployments and Fastjson 1.x versions. Organizations in multiple sectors have already been targeted, and defenders are urged to move to Fastjson 2.x or enable SafeMode to reduce risk. #Fastjson #CVE-2026-16723 #Alibaba #Imperva #ThreatBook
Keypoints
- CVE-2026-16723 is a critical-severity Fastjson RCE flaw with a CVSS score of 9.
- The vulnerability affects Fastjson 1.2.68 through 1.2.83 and is not present in Fastjson 2.x.
- Exploitation works in default configurations and does not require authentication or AutoType enablement.
- Attackers can use crafted JSON with a malicious @type value to trigger code execution on vulnerable servers.
- Imperva reported attacks against organizations in the US, Singapore, and Canada across multiple sectors.
Read More: https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/