← Back to Feed

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

CVE-2026-16723

July 25, 2026 · The Hacker News · Severity: CRITICAL

Attackers are targeting a critical unauthenticated RCE vulnerability (CVE-2026-16723, CVSS 9.0) in Fastjson 1.x, Alibaba's JSON library for Java. In Spring Boot applications, a malicious JSON request can execute code with Java process privileges without authentication. The confirmed chain affects Fastjson 1.2.68 through 1.2.83 with SafeMode disabled. As of July 25, 2026, Alibaba had not released a fixed Fastjson 1.x version, recommending migration to Fastjson2 as the long-term fix.

Key Takeaways

  • CVE-2026-16723 is a critical unauthenticated RCE in Fastjson 1.x (CVSS 9.0) affecting Spring Boot applications. Confirmed vulnerable range: Fastjson 1.2.68 through 1.2.83 with SafeMode disabled AutoType can remain disabled.
  • Immediate mitigations include enabling SafeMode or using the 1.2.83_noneautotype variant.
  • Attackers can execute code without authentication or classpath gadgets using crafted JSON requests.
☕ Buy a Coffee