Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are focusing on a serious vulnerability in Fastjson, Alibaba's JSON library for Java, according to security companies ThreatBook and Imperva. A malicious JSON request with Java process rights can run code in impacted Spring Boot apps without authentication.
The vulnerability, which is tracked as CVE-2026-16723, has a CVSS score of 9.0 according to Alibaba. Fastjson 1.2.68 through 1.2.83, a Spring Boot executable fat-JAR, a network-reachable path that transmits attacker-controlled JSON to an impacted parser, and SafeMode left at its disabled default are all necessary for the verified chain. There is no need for a classpath device, and AutoType can be left disabled.
Alibaba had not yet published a fixed version of Fastjson 1.x as of July 25. Businesses that are unable to mov...





