A critical remote code execution vulnerability tracked as CVE-2026-16723 has been identified in Alibaba Fastjson versions up to 1.2.83, the widely used JSON parsing library for Java. Security firms ThreatBook and Imperva have confirmed active exploitation in the wild, with attackers targeting Spring Boot applications to achieve unauthenticated code execution. Critically, no patch is currently available, leaving all affected deployments exposed.
The vulnerability, carrying a CVSS score of 9.0 as assigned by Alibaba, stems from improper input validation in Fastjson's JSON processing logic. A remote, unauthenticated attacker can submit a specially crafted malicious JSON request that triggers arbitrary code execution with the privileges of the underlying Java process, requiring no prior authentication or user interaction.
With no remediation available at time of reporting and active exploitation already underway, organisations relying on Fastjson 1.x — particularly within Spring Boot deployments — face immediate and material risk. Defenders are urged to implement compensating controls and closely monitor for anomalous JSON request patterns while awaiting vendor guidance.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.