Wire · regulatory
Unpatched Fastjson 1.x RCE Vulnerability Threatens Spring Boot Fat-JAR Applications
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 26 July 2026 · Fusion42 review
An unpatched remote code execution vulnerability in Alibaba's Fastjson 1.2.68–1.2.83 library is being actively exploited in the wild against Spring Boot applications; it requires no authentication and allows arbitrary code execution through malicious JSON payloads.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software, and 3 sources have reported it between 25 Jul 2026 and 26 Jul 2026.
◆ ◆ The Wire takeaway
If you ship a Spring Boot app using Fastjson 1.2.68–1.2.83, you have an unpatched RCE live in production right now and attackers are scanning for it. Upgrade or air-gap that endpoint this week—there is no vendor patch coming.
◆ Coverage
3 sources · first reported 25 Jul 2026 · latest 26 Jul 2026
◆ Related on Wire
◆ Topics