Exploited in the wild Fastjson 1.x rce Alibaba web-app
Hackers target US firms in FastJson RCE zero-day attacks
CVE Tools coverage
A critical zero-day vulnerability in Alibaba's FastJson library is being actively exploited against U.S.-based companies, enabling remote code execution without user interaction or elevated privileges. The flaw, tracked as CVE-2026-16723, impacts versions 1.2.68 through 1.2.83 and has been observed in attacks spanning multiple industries including finance, healthcare, and retail. Security researchers have confirmed global targeting, with incidents reported in Singapore and Canada as well. Alibaba warns that no official fix is planned for the outdated 1.x branch, urging users to switch to safe deployment models or upgrade to fastjson2.