Critical

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker News
Actively Exploited

Overview

Attackers are exploiting a serious vulnerability in Fastjson, a JSON library developed by Alibaba for Java applications, particularly those using Spring Boot. This flaw, identified as CVE-2026-16723, allows unauthorized code execution with the privileges of the Java process, posing significant risks to affected systems. The vulnerability has a high severity rating of 9.0, indicating it could lead to severe consequences if not addressed. Currently, there are no patches available to fix this issue, which increases the urgency for developers and organizations using Fastjson to take immediate protective measures. Security firms have reported that this vulnerability is being actively exploited, making it critical for users to assess their systems and implement necessary safeguards.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Fastjson library (1.x), Spring Boot applications
  • Action Required: Developers are advised to review their use of Fastjson and implement input validation and sanitization to mitigate risks.
  • Timeline: Newly disclosed

Original Article Summary

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires

Impact

Fastjson library (1.x), Spring Boot applications

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Developers are advised to review their use of Fastjson and implement input validation and sanitization to mitigate risks. Additionally, consider using alternative libraries if possible until a patch is released.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, RCE, and 1 more.

Related Coverage

Malicious sites use JavaScript to build malware in browser memory

BleepingComputer

A large-scale malvertising campaign is targeting internet users by creating fake websites that mimic popular platforms like Solana, Luno, and TradingView. These sites contain malicious JavaScript code that instructs web browsers to construct malware directly in memory, bypassing traditional security measures. This method makes it difficult for security software to detect or block the malware, increasing the risk for unsuspecting users who visit these sites. As a result, individuals looking to trade or invest in cryptocurrencies are particularly vulnerable. The campaign not only threatens individual users but also raises concerns about the overall security of online financial platforms.

Jul 25, 2026

ShinyHunters data leaks fuel $2,000 sextortion email scam

BleepingComputer

The ShinyHunters extortion group has leaked email addresses from various data breaches, which are now being exploited in a sextortion scam. Attackers are sending emails to individuals, claiming to have compromising information and demanding $2,000 in Bitcoin to avoid sharing it. This scam is particularly concerning because it targets people whose email addresses were exposed in previous breaches, making the threats more credible. Victims may feel pressured to comply due to fear of reputational damage or privacy violations. As these tactics become more prevalent, individuals should be cautious about sharing personal information online and consider using additional security measures to protect their data.

Jul 25, 2026

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

The Hacker News

Security researchers have released exploit code for a vulnerability in GitLab that allows authenticated users to execute commands as the 'git' user on certain self-managed servers. This flaw affects GitLab version 18.11.3 and earlier, which had a patch issued on June 10, 2023. If a user can push to a project, they can exploit the vulnerability by committing a specially crafted Jupyter notebook. This action reveals sensitive heap memory data, enabling unauthorized command execution. Organizations using vulnerable versions of GitLab should prioritize applying the patch to prevent potential abuse of this exploit, especially in environments where multiple users have access to project repositories.

Jul 25, 2026

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

The Hacker News

Recent research from CTM360 reveals a troubling shift in phishing tactics targeting the insurance sector. Traditionally, attackers would trick victims into providing their login credentials, then use this information to compromise accounts later. However, the new approach involves real-time account hijacking, where attackers act immediately upon obtaining credentials. This evolution poses a significant risk not only to individuals but also to insurance companies, as it allows for quicker financial exploitation and potentially greater losses. Users must remain vigilant against these sophisticated phishing schemes, which are becoming increasingly effective at bypassing security measures.

Jul 25, 2026

OpenAI confirms ChatGPT is down worldwide

BleepingComputer

ChatGPT, the popular AI chatbot developed by OpenAI, is currently experiencing widespread connectivity issues affecting users globally. The outages have been reported across various regions, disrupting access for users who rely on the AI for conversation and assistance. OpenAI has acknowledged the problem but has not specified the cause or provided a timeline for resolution. This downtime is significant as it impacts many individuals and businesses that utilize ChatGPT for various applications, from customer service to content creation. Users are left waiting for updates on when the service will be restored.

Jul 25, 2026

Rockwell Patches Code Execution Flaws in Arena Simulation Software

SecurityWeek

Rockwell has released patches for its Arena simulation software after researchers identified serious code execution vulnerabilities. These flaws could allow attackers to exploit the software, potentially impacting industrial organizations that rely on it for simulation and modeling. If left unaddressed, these vulnerabilities could lead to unauthorized access and manipulation of critical systems. Users of Arena are urged to apply the patches promptly to safeguard their operations and data. This situation serves as a reminder for companies to regularly update their software to protect against emerging threats.

Jul 25, 2026