static-urls · Crawled Jul 30, 2026

Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation

2 IoCs
Read original article ↗

AI Summary

A remote code execution (RCE) vulnerability in Fastjson versions ≤ 1.2.83 is under active exploitation in the wild. The vulnerability allows unauthenticated attackers to execute arbitrary code on affected servers by sending specially crafted JSON payloads, without requiring user privileges or victim interaction. Exploitation is possible when Fastjson SafeMode is not enabled. ThreatBook TDP has detected active attacks and provides detection capabilities via signature S3100181015. The recommended mitigations include enabling SafeMode, blocking malicious payloads at the perimeter, and migrating to Fastjson 2.x, as no official patch is available for the 1.x series.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename @type":"jar:file:. Details →
Filename @type":"jar:http:.. Details →