hacker-news · Crawled Jul 25, 2026
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Read original article ↗AI Summary
Attackers are actively exploiting a critical unpatched remote code execution vulnerability, CVE-2026-16723, in Fastjson 1.x versions 1.2.68 through 1.2.83. The flaw affects Spring Boot applications using executable fat-JARs and allows code execution without authentication by leveraging malicious JSON input with crafted @type values. Exploitation has been observed in the wild, primarily targeting organizations in the United States, with additional activity in Singapore and Canada. Alibaba has not released a patch for Fastjson 1.x and recommends enabling SafeMode or migrating to Fastjson2.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.