CVE-2026-16723
Remote Code Execution in fastjson 1.2.68–1.2.83
Description
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
In plain language
AI Act nowCVE-2026-16723 is a serious remote code execution flaw in Fastjson 1.2.68–1.2.83, and typical small businesses should treat it as urgent if they run software that uses this exact Fastjson version (it’s being exploited in the wild).
CVE-2026-16723 is an unauthenticated remote code execution issue in Fastjson (versions 1.2.68 through 1.2.83) triggered by crafted JSON input that abuses how the library processes certain data, and it is exploitable under Fastjson’s default configuration without AutoType enablement or classpath gadgets.
What to do now
- Check where Fastjson is used (your app, plugins, or dependencies) and confirm the Fastjson version is between 1.2.68 and 1.2.83.
- If you are on 1.2.68–1.2.83, stop taking untrusted JSON inputs through that Fastjson code path immediately (block the endpoints, or temporarily disable features that parse attacker-controlled JSON).
- Remove Fastjson from the affected component(s) by upgrading to a Fastjson release outside 1.2.68–1.2.83; if no fixed version is available for your stack, replace the JSON library used by your application.
- Hunt for active exploitation by reviewing application and system logs for evidence of unusual JSON payloads and unexpected process/network activity after JSON parsing.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- RCE-уязвимость в Fastjson используется в атакахru-ru·Хакер (xakep.ru)· Exploited Fastjson rce
- Srsly Risky Biz: Chipping Away at Chinese AI Risksen·Risky Business News· Research ai-ml
- Unpatched Fastjson Vulnerability Exploited in Attacksen-us·SecurityWeek· Exploited Fastjson 1.x rce
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flawen·The Hacker News· Exploited VeloCloud Orchestrator rce
- Hackers target US firms in FastJson RCE zero-day attacksen-us·BleepingComputer· Exploited Fastjson 1.x rce
- A JSON RCE bug is about to rock the Java worlden·Risky Business News· Exploited Fastjson rce
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Availableen·The Hacker News· Exploited Fastjson rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-16723 and every CVE in our database. Create a free account — no credit card required.
Create Free Account