< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

Critical Fastjson RCE Vulnerability Exploited in US

A critical remote code execution flaw (CVE‑2026‑16723, CVSS 9.0) has been identified in Alibaba's Fastjson library versions 1.2.68 through 1.2.83 when used within Spring Boot applications. Security firms ThreatBook and Imperva reported active exploitation targeting financial services, healthcare, retail and other sectors, primarily in the United States. The attack chain works without AutoType enablement or a classpath gadget and requires a Spring Boot fat‑JAR that processes attacker‑controlled JSON.

Alibaba released an advisory on July 21, noting no patched Fastjson 1.x version is available as of July 25. Recommended mitigations are enabling SafeMode (‑Dfastjson.parser.safeMode=true) or using the restricted 1.2.83_noneautotype build, with a longer‑term migration to Fastjson2. The vulnerability was discovered by Kirill Firsov of FearsOff Cybersecurity. CISA has not listed the flaw as exploited, and it remains absent from its Known Exploited Vulnerabilities catalog.