← Back

Wire · regulatory

Alibaba's Fastjson 1.x Hit by Active RCE Exploits, No Patch

Published

26 July 2026

Topic

regulatory

Sectors

CybersecurityData Infrastructure

Geography

United States

Source

Read at aiweekly.co

Verified

Fusion42 · 26 July 2026 · Fusion42 review

Alibaba's Fastjson 1.x library (versions 1.2.68–1.2.83) is under active remote code execution exploitation via CVE-2026-16723 (CVSS 9.0) in Spring Boot deployments with SafeMode disabled; Alibaba has released no patch for the 1.x branch and recommends either enabling SafeMode, using a restricted build, or migrating to Fastjson2.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Data Infrastructure. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

If you run Fastjson 1.x behind any internet-facing JSON endpoint, you have an unpatched remote code execution hole being actively exploited right now. The JVM flag `-Dfastjson.parser.safeMode=true` closes it today; the migration to Fastjson2 is your this-quarter deadline.

Related on Wire

Topics

CybersecurityData Infrastructurefastjsonrce-vulnerabilityspring-bootunpatchedactive-exploitationjava