Unpatched Fastjson Vulnerability Exploited in Attacks

Unpatched Fastjson Vulnerability Exploited in Attacks
Threat actors are actively exploiting a critical Fastjson remote code execution flaw, tracked as CVE-2026-16723, affecting widely used Spring Boot fat-jar deployments and Fastjson 1.x versions. Organizations in multiple sectors have already been targeted, and defenders are urged to move to Fastjson 2.x or enable SafeMode to reduce risk. #Fastjson #CVE-2026-16723 #Alibaba #Imperva #ThreatBook

Keypoints

  • CVE-2026-16723 is a critical-severity Fastjson RCE flaw with a CVSS score of 9.
  • The vulnerability affects Fastjson 1.2.68 through 1.2.83 and is not present in Fastjson 2.x.
  • Exploitation works in default configurations and does not require authentication or AutoType enablement.
  • Attackers can use crafted JSON with a malicious @type value to trigger code execution on vulnerable servers.
  • Imperva reported attacks against organizations in the US, Singapore, and Canada across multiple sectors.

Read More: https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/