Attackers are exploiting CVE-2026-16723, a critical Fastjson flaw in Spring Boot fat-JAR applications that can lead to unauthenticated code execution with Java process privileges. ThreatBook and Imperva reported in-the-wild activity, while Alibaba has not yet released a patched Fastjson 1.x version and recommends SafeMode or migration to Fastjson2. #CVE-2026-16723 #Fastjson #SpringBoot #Alibaba #ThreatBook #Imperva #KirillFirsov #FearsOffCybersecurity
Keypoints
- Attackers are targeting a critical Fastjson flaw tracked as CVE-2026-16723.
- The issue affects Spring Boot fat-JAR applications using Fastjson 1.2.68 through 1.2.83.
- A crafted JSON request can trigger code execution without authentication.
- ThreatBook and Imperva reported observed exploitation activity in the wild.
- Alibaba recommends enabling SafeMode or migrating to Fastjson2 as the long-term fix.
Read More: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html