← All briefs
Brief·2 sources25 Jul 2026

CVE-2026-16723 Actively Exploited In Fastjson 1.x RCE Attacks

zero-day-exploitvulnerability-disclosureinitial-accessmalwarepatch-management

Summary

A critical remote code execution vulnerability tracked as CVE-2026-16723 has been identified in Alibaba Fastjson versions up to 1.2.83, the widely used JSON parsing library for Java. Security firms ThreatBook and Imperva have confirmed active exploitation in the wild, with attackers targeting Spring Boot applications to achieve unauthenticated code execution. Critically, no patch is currently available, leaving all affected deployments exposed.

The vulnerability, carrying a CVSS score of 9.0 as assigned by Alibaba, stems from improper input validation in Fastjson's JSON processing logic. A remote, unauthenticated attacker can submit a specially crafted malicious JSON request that triggers arbitrary code execution with the privileges of the underlying Java process, requiring no prior authentication or user interaction.

With no remediation available at time of reporting and active exploitation already underway, organisations relying on Fastjson 1.x — particularly within Spring Boot deployments — face immediate and material risk. Defenders are urged to implement compensating controls and closely monitor for anomalous JSON request patterns while awaiting vendor guidance.

Timeline

  1. 25 July 2026
    Active exploitation confirmed by ThreatBook and Imperva
    Security firms ThreatBook and Imperva reported that attackers were actively exploiting CVE-2026-16723 in the wild, targeting Spring Boot applications to achieve unauthenticated remote code execution. No patch was available at the time of reporting.
  2. 23 July 2026
    CVE-2026-16723 catalogued as critical Fastjson input validation flaw
    VulDB published an entry for CVE-2026-16723, classifying it as a critical remote-exploitable improper input validation vulnerability affecting Alibaba Fastjson up to version 1.2.83. No exploit was noted as publicly available at this stage.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.

CVE-2026-16723 Actively Exploited In Fastjson 1.x RCE Attacks — Deltabridge