Active Exploitation25 July 2026
Fastjson 1.x RCE (CVE-2026-16723) Is Under Active Attack — No Patch Yet
A critical, unauthenticated RCE in Alibaba's Fastjson 1.x is being exploited against Spring Boot fat-JAR deployments, and there is still no fixed 1.x release.
fastjsonrcejava