Home / Jul 26, 2026 / Story
0
#1 The Hacker News general July 25, 2026 at 12:52 UTC

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

By [email protected] (The Hacker News)

AI Summary

CVE-2026-16723, a critical unauthenticated RCE vulnerability in Alibaba's Fastjson 1.x Java library (CVSS 9.0), is being actively exploited in the wild with no patch currently available. ThreatBook and Imperva confirmed that attackers can execute arbitrary code without authentication in affected Spring Boot applications by sending a malicious JSON request. Security practitioners running Spring Boot with Fastjson 1.x should treat this as an emergency given active exploitation and the absence of a vendor fix.

Relevance score: 88.0/100

# More from July 26