Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 5 sources · 3 days · First seen · Last updated
Categories: TECHNOLOGY
Exploitation of Fastjson 1.x RCE flaw
Entities: Alibaba Group · Fastjson · ThreatBook · Imperva · Spring Boot
Overview
In late July 2026 security firms ThreatBook and Imperva reported active exploitation of a critical remote‑code‑execution vulnerability (CVE‑2026‑16723) in Alibaba’s Fastjson 1.x library, affecting versions 1.2.68 through 1.2.83. The flaw, scoring 9.0 on the CVSS scale, can be triggered in Spring Boot applications packaged as executable fat‑JARs without any AutoType setting or class‑path gadget. Attackers supply malicious JSON that causes the library to load attacker‑controlled classes, allowing arbitrary code execution with the privileges of the Java process.
Exploitation was observed primarily against organizations in the United States, spanning financial services, healthcare, retail and other sectors. Alibaba issued an advisory on 21 July, noting that no patched 1.x version was available as of 25 July. Recommended short‑term mitigations include enabling SafeMode (‑Dfastjson.parser.safeMode=true) or using the 1.2.83_noneautotype build, with a longer‑term migration to Fastjson 2 advised. The U.S. National Vulnerability Database added the CVE on 23 July, but the vulnerability remains absent from CISA’s Known Exploited Vulnerabilities catalog.
Timeline
-
about 23 hours ago
[TECHNOLOGY] 3 sourcesCritical Remote Code Execution Flaw in Alibaba's Fastjson 1.x ExploitedA critical RCE vulnerability (CVE‑2026‑16723) in Alibaba’s Fastjson 1.x (versions 1.2.68‑1.2.83) is actively exploited, affecting Spring Boot fat‑JARs; no patch yet, users urged to enable SafeMode or migrate to
-
3 days ago
[TECHNOLOGY] 2 sourcesCritical Fastjson RCE Vulnerability Exploited in USA critical Fastjson RCE flaw (CVE‑2026‑16723) affecting Spring Boot apps is being exploited in the US, with no patch yet; mitigation via SafeMode or migration to Fastjson2 advised.
Sources
blogspan.net · digital-magazin.de · doppiogusto.com · infoguerra.com.br · thehackernews.com