Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fastjson Spring Boot unauthenticated RCE (CVE-2026-16723)

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-16723 is a Fastjson RCE affecting Spring Boot fat-JAR deployments, letting attacker-controlled JSON execute with the Java process's privileges. ThreatBook and Imperva said they saw in-the-wild exploitation, while Alibaba had not released a fixed Fastjson 1.x build as of July 25. The confirmed chain requires Fastjson 1.2.68 through 1.2.83, a network-reachable parser path, and SafeMode left disabled. Mitigations include enabling -Dfastjson.parser.safeMode=true or using com.alibaba:fastjson:1.2.83_noneautotype.

Related Happenings

Alibaba Fastjson SafeMode mitigation for CVE-2026-16723

Advisory/Mitigation
H score44 First: 25.07.2026 15:52 Last: 25.07.2026 15:52 Sources 1

How related: Organizations that cannot migrate immediately should enable SafeMode with -Dfastjson.parser.safeMode=true or use com.alibaba:fastjson:1.2.83_noneautotype.

About this happening: Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code...

CISA emergency patch deadline for React2Shell

Public Sector Action
H score37 First: 12.12.2025 10:41 Last: 12.12.2025 10:41 Sources 1

About this happening: CISA urged federal agencies to patch React2Shell by December 12, 2025, tightening the remediation window while widespread exploitation is underway. The directi...

Timeline

  1. 25.07.2026 15:52 1 articles · 1h ago

    Alibaba publishes advisory for CVE-2026-16723 in Fastjson

    Initial Disclosure

    Alibaba published an advisory for CVE-2026-16723 after responsible disclosure by Kirill Firsov of FearsOff Cybersecurity, warning that affected Spring Boot applications using Fastjson 1.2.68 through 1.2.83 can execute attacker-controlled JSON without authentication when SafeMode remains disabled.

    Show sources
  2. 25.07.2026 15:52 1 articles · 1h ago

    ThreatBook captures in-the-wild Fastjson exploitation

    Exploitation Observed

    ThreatBook said it had captured in-the-wild exploitation of CVE-2026-16723 after adding detection support, confirming active targeting of Fastjson Spring Boot deployments that match the affected 1.2.68 through 1.2.83 chain.

    Show sources
  3. 25.07.2026 15:52 2 articles · 1h ago

    Imperva sees Fastjson activity across U.S. financial, healthcare, computing, and retail targets

    Campaign Scope Update

    Imperva reported exploitation activity against financial services, healthcare, computing, retail, and other organizations, mostly in the United States with smaller volumes in Singapore and Canada, while Alibaba had still not released a fixed Fastjson 1.x version as of July 25.

    Show sources