The record
Written from the 3 reports below. Nothing here is unsourced.
- Security researchers report that attackers are actively exploiting a critical remote code execution flaw in Alibaba's Fastjson, a widely used open-source Java library for reading JSON data, with US organizations across multiple industries among the targets.
- The flaw is rated 9.0 out of 10 for severity and affects Fastjson versions 1.2.68 through 1.2.83 - and unusually, there is no patched version yet, so the usual advice to simply update does not apply.
- Interim defenses are limited to disabling the library's riskiest feature: operators can enable SafeMode with a startup flag or switch to a special 'noneautotype' build.
- Because Fastjson is often bundled invisibly inside other software, many organizations may not realize they run it at all.
- In a related disclosure, networking vendor Arista separately warned that a critical flaw in its VeloCloud Orchestrator is also being exploited in the wild, with patches available for specific release trains.
- Coverage from The Hacker News and BleepingComputer is uniformly cautionary with little disagreement; unknowns include who the attackers are, how many victims there are, and when an official Fastjson fix will land.
What to watch next
- Watch for an official Fastjson patch and vendor advisories
- Expect CISA KEV listing to trigger US federal patch deadlines
- Check whether your Java apps transitively bundle Fastjson
- Track Arista VeloCloud advisories for new exploitation indicators
What changed3
Every report on this story, newest first. Times are when each outlet published.
The Hacker News[1]
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsBleepingComputer[2]
Hackers target US firms in FastJson RCE zero-day attacksThe Hacker News[3]
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Why it matters6
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- US organizations running Fastjson 1.2.68-1.2.83 remote code execution· immediate
- Java applications with transitive Fastjson dependencies unpatched dependency exposure· immediate
- Fastjson operators and security teams emergency workaround required· days
- Exploited organizations follow on intrusion· weeks
- VeloCloud Orchestrator deployments infrastructure compromise risk· immediate
- Enterprise patch programs inventory and mitigation burden· days
Coverage2
Filed from India ×2, United States ×1
Named United States · Singapore · Canada · VeloCloud Orchestrator · VeloCloud SD-WAN · Alibaba · Arista · CISA · Fastjson · FearsOff · FearsOff Cybersecurity · GitHub · Hackers · Imperva
- The Hacker NewsNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups[1]English national· neutral

- BleepingComputerHackers target US firms in FastJson RCE zero-day attacks[2]International· neutral

- The Hacker NewsFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available[3]English national· neutral

The 3 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.