As cited
Copy frozen at (site build).
vulnerabilities
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java. The flaw allows unauthenticated code execution in affected Spring Boot applications with a CVSS score of 9.0. No patched version is currently available.
Why it matters: Organizations running Fastjson 1.x in Spring Boot deployments face immediate remote code execution risk; immediate assessment and mitigation planning are required until a patch is released.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java. The flaw allows unauthenticated code execution in affected Spring Boot applications with a CVSS score of 9.0. No patched version is currently available.
Why it matters: Organizations running Fastjson 1.x in Spring Boot deployments face immediate remote code execution risk; immediate assessment and mitigation planning are required until a patch is released.
- Source published
- First seen by Cybersecurity Tracker