← Back

Wire · regulatory

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Published

25 July 2026

Topic

regulatory

Sectors

Enterprise SoftwareCybersecurity

Geography

China

Source

Read at thehackernews.com

Verified

Fusion42 · 25 July 2026 · Fusion42 review

Alibaba's Fastjson 1.x library (versions 1.2.68–1.2.83) is under active attack via a critical RCE vulnerability (CVE-2026-16723, CVSS 9.0) that requires no AutoType or gadget enablement. No patch is available; affected Spring Boot applications must enable SafeMode or migrate to Fastjson2.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity, and 3 sources have reported it between 25 Jul 2026 and 26 Jul 2026.

◆ The Wire takeaway

If you ship Java on Spring Boot, you're running Fastjson 1.2.68–1.2.83 and it's being exploited right now—and Alibaba hasn't patched it yet. Flip SafeMode on or pull the non-AutoType build this week; migration to Fastjson2 is the permanent fix but takes time you don't have.

Coverage

3 sources · first reported 25 Jul 2026 · latest 26 Jul 2026

Related on Wire

Topics

Enterprise SoftwareCybersecurityfastjson-rcespring-boot-vulnerabilityjava-librarieszero-patch-windowsafemode-workaround