CVE Tools
Back to feed
Exploited in the wild Fastjson rce Java libraries Alibaba web-app

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Attackers are actively exploiting a critical remote code execution (RCE) vulnerability in Fastjson, Alibaba's widely used Java JSON library. Tracked as CVE-2026-16723, this flaw affects versions 1.2.68 through 1.2.83 and enables unauthenticated attackers to execute arbitrary code under certain conditions involving Spring Boot applications. As of July 25, no official patch for the 1.x branch has been released, leaving users vulnerable unless they apply mitigations like enabling SafeMode or upgrading to Fastjson2.