Exploited in the wild Fastjson rce Java applications Alibaba web-app
A JSON RCE bug is about to rock the Java world
CVE Tools coverage
A critical vulnerability in Alibaba's Fastjson library, CVE-2026-16723, is being actively exploited to perform unauthenticated remote code execution attacks. The flaw affects the widely used 1.x branch of Fastjson, particularly when deployed as part of Spring Boot applications. Threat actors have already targeted multiple industries, including finance and healthcare, with a focus on U.S.-based organizations. While no official patch has been issued, Alibaba recommends switching to the safer 2.x branch or activating SafeMode in existing deployments.