Fastjson Spring Boot unauthenticated RCE (CVE-2026-16723)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-16723 is a Fastjson RCE affecting Spring Boot fat-JAR deployments, letting attacker-controlled JSON execute with the Java process's privileges. ThreatBook and Imperva said they saw in-the-wild exploitation, while Alibaba had not released a fixed Fastjson 1.x build as of July 25. The confirmed chain requires Fastjson 1.2.68 through 1.2.83, a network-reachable parser path, and SafeMode left disabled. Mitigations include enabling -Dfastjson.parser.safeMode=true or using com.alibaba:fastjson:1.2.83_noneautotype.
Related Happenings
Alibaba Fastjson SafeMode mitigation for CVE-2026-16723
Advisory/Mitigation
H score44
First: 25.07.2026 15:52
Last: 25.07.2026 15:52
Sources 1
How related:
Organizations that cannot migrate immediately should enable SafeMode with -Dfastjson.parser.safeMode=true or use com.alibaba:fastjson:1.2.83_noneautotype.
About this happening:
Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code...
Alibaba Fastjson SafeMode mitigation for CVE-2026-16723
Advisory/MitigationHow related: Organizations that cannot migrate immediately should enable SafeMode with -Dfastjson.parser.safeMode=true or use com.alibaba:fastjson:1.2.83_noneautotype.
About this happening: Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code...
CISA emergency patch deadline for React2Shell
Public Sector Action
H score37
First: 12.12.2025 10:41
Last: 12.12.2025 10:41
Sources 1
About this happening:
CISA urged federal agencies to patch React2Shell by December 12, 2025, tightening the remediation window while widespread exploitation is underway. The directi...
CISA emergency patch deadline for React2Shell
Public Sector ActionAbout this happening: CISA urged federal agencies to patch React2Shell by December 12, 2025, tightening the remediation window while widespread exploitation is underway. The directi...
Timeline
-
25.07.2026 15:52 1 articles · 1h ago
Alibaba publishes advisory for CVE-2026-16723 in Fastjson
Initial DisclosureAlibaba published an advisory for CVE-2026-16723 after responsible disclosure by Kirill Firsov of FearsOff Cybersecurity, warning that affected Spring Boot applications using Fastjson 1.2.68 through 1.2.83 can execute attacker-controlled JSON without authentication when SafeMode remains disabled.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
-
25.07.2026 15:52 1 articles · 1h ago
ThreatBook captures in-the-wild Fastjson exploitation
Exploitation ObservedThreatBook said it had captured in-the-wild exploitation of CVE-2026-16723 after adding detection support, confirming active targeting of Fastjson Spring Boot deployments that match the affected 1.2.68 through 1.2.83 chain.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
-
25.07.2026 15:52 1 articles · 1h ago
CISA-ADP marks CVE-2026-16723 exploitation as none
Industry Or Public Sector UpdateA CISA-ADP assessment dated July 23 marked exploitation as none for CVE-2026-16723, creating a public-sector status that did not match vendor observations of live targeting.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
-
25.07.2026 15:52 2 articles · 1h ago
Imperva sees Fastjson activity across U.S. financial, healthcare, computing, and retail targets
Campaign Scope UpdateImperva reported exploitation activity against financial services, healthcare, computing, retail, and other organizations, mostly in the United States with smaller volumes in Singapore and Canada, while Alibaba had still not released a fixed Fastjson 1.x version as of July 25.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52