< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 5 sources · 3 days · First seen · Last updated

Categories: TECHNOLOGY

Exploitation of Fastjson 1.x RCE flaw

Entities: Alibaba Group · Fastjson · ThreatBook · Imperva · Spring Boot

Overview

In late July 2026 security firms ThreatBook and Imperva reported active exploitation of a critical remote‑code‑execution vulnerability (CVE‑2026‑16723) in Alibaba’s Fastjson 1.x library, affecting versions 1.2.68 through 1.2.83. The flaw, scoring 9.0 on the CVSS scale, can be triggered in Spring Boot applications packaged as executable fat‑JARs without any AutoType setting or class‑path gadget. Attackers supply malicious JSON that causes the library to load attacker‑controlled classes, allowing arbitrary code execution with the privileges of the Java process.

Exploitation was observed primarily against organizations in the United States, spanning financial services, healthcare, retail and other sectors. Alibaba issued an advisory on 21 July, noting that no patched 1.x version was available as of 25 July. Recommended short‑term mitigations include enabling SafeMode (‑Dfastjson.parser.safeMode=true) or using the 1.2.83_noneautotype build, with a longer‑term migration to Fastjson 2 advised. The U.S. National Vulnerability Database added the CVE on 23 July, but the vulnerability remains absent from CISA’s Known Exploited Vulnerabilities catalog.

Timeline

  1. about 23 hours ago

    [TECHNOLOGY] 3 sources
    Critical Remote Code Execution Flaw in Alibaba's Fastjson 1.x Exploited

    A critical RCE vulnerability (CVE‑2026‑16723) in Alibaba’s Fastjson 1.x (versions 1.2.68‑1.2.83) is actively exploited, affecting Spring Boot fat‑JARs; no patch yet, users urged to enable SafeMode or migrate to

  2. 3 days ago

    [TECHNOLOGY] 2 sources
    Critical Fastjson RCE Vulnerability Exploited in US

    A critical Fastjson RCE flaw (CVE‑2026‑16723) affecting Spring Boot apps is being exploited in the US, with no patch yet; mitigation via SafeMode or migration to Fastjson2 advised.

Sources

blogspan.net · digital-magazin.de · doppiogusto.com · infoguerra.com.br · thehackernews.com