ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Fastjson 1.x RCE (CVE-2026-16723) Exploited in Unauthenticated Spring Boot Attacks

Source headline: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Threat level Critical
Signal strength 90/100
Source confidence 1 source
Published 4 hours ago

Intelligence Summary

ThreatBook and Imperva report active targeting of a critical Fastjson 1.x remote code execution flaw. A crafted malicious JSON request can trigger code execution in affected Spring Boot applications without authentication. The payload runs with the privileges of the Java process, increasing potential impact. The issue is tracked as CVE-2026-16723 and carries an Alibaba-assigned CVSS score of 9.0. With no patch reported, defenders should assess exposure and apply compensating mitigations immediately.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#rce #unauthenticated #java #cve-2026-16723 #fastjson #spring-boot
Original reporting The Hacker News Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Open original source