bleeping-computer · Crawled Jul 28, 2026
Hackers target US firms in FastJson RCE zero-day attacks
Read original article ↗AI Summary
Hackers are actively exploiting a zero-day remote code execution vulnerability, CVE-2026-16723, in the FastJson Java library to target U.S.-based organizations across multiple sectors including financial services, healthcare, and retail. The vulnerability exists in FastJson versions 1.2.68 through 1.2.83 and is exploited without requiring user interaction or elevated privileges, primarily affecting Spring Boot fat-JAR deployments. Alibaba has confirmed the issue but no patch is available, and FastJson 1.x is no longer maintained, leaving affected systems exposed.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.