Wire · regulatory
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 25 July 2026 · Fusion42 review
Alibaba's Fastjson 1.x library (versions 1.2.68–1.2.83) is under active attack via a critical RCE vulnerability (CVE-2026-16723, CVSS 9.0) that requires no AutoType or gadget enablement. No patch is available; affected Spring Boot applications must enable SafeMode or migrate to Fastjson2.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
If you ship Java on Spring Boot, you're running Fastjson 1.2.68–1.2.83 and it's being exploited right now—and Alibaba hasn't patched it yet. Flip SafeMode on or pull the non-AutoType build this week; migration to Fastjson2 is the permanent fix but takes time you don't have.
◆ Related on Wire
◆ Topics