Security · 22h ago
Critical Fastjson Flaw Under Active Attack, No Patch Available
Attackers are exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson library for Java, with a CVSS score of 9.0. The flaw allows unauthenticated code execution in Spring Boot applications via malicious JSON requests. Security firms ThreatBook and Imperva report active attacks, but no patch has been released.
Meridian48 take
The lack of a patch for a flaw this severe underscores the risks of relying on unmaintained open-source libraries in production.
Read the full reporting
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available →
The Hacker News
fastjsonrce-vulnerability