CVE-2026-16723: Fastjson 1.x RCE Exploited, No Patch
🔴 Critical | Source: The Hacker News A critical remote code execution vulnerability (CVE-2026-16723) in Fastjson 1.x, Alibaba’s widely-used Java JSON library, is being actively exploited in the wild with no patch currently available. Attackers can send a crafted JSON request to vulnerable Spring Boot applications and execute arbitrary code without authentication, inheriting the full privileges of the Java process. The absence of a fix makes this particularly dangerous for any organisation running Fastjson 1.x in production. ...