Digest
CRITICAL

Fastjson 1.x RCE Vulnerability Actively Exploited, No Patch Available

Attackers are actively exploiting a critical remote code execution (RCE) vulnerability, CVE-2026-16723, in Alibaba’s Fastjson 1.x library for Java. This flaw allows unauthenticated attackers to execute arbitrary code with the privileges of the Java process in affected Spring Boot applications by sending a malicious JSON request. With a CVSS score of 9.0, the vulnerability currently has no official patch, making it a significant threat to vulnerable systems.

← Back to the feed

Trending Tags