← Back to feed
cybersecurityCVSS 9.0 criticalCVE-2026-16723CVE-2026-16812CVE-2025-686862 sources · 3h ago

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms report active exploitation of a critical Fastjson RCE vulnerability with no patched version currently available.

AffectedUnited StatesSingaporeCanada Alibaba Canada CISA Fastjson FearsOff FearsOff Cybersecurity GitHub Hackers Imperva Kirill Firsov Singapore Spring Boot
2 outlets · 2 origins · Balanced
India × 2United States × 2

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Neutral reportingReporting that CVE-2026-16723 in Fastjson 1.2.68–1.2.83 is under active exploitation with no vendor patch yet available

Security outlets and CVE sources report that attackers are actively exploiting a critical RCE flaw in Alibaba/Fastjson's default configuration across versions 1.2.68 through 1.2.83, with mitigation limited to enabling SafeMode or switching to a noneautotype build. Coverage emphasizes that no patched release has been issued and that exploitation is affecting US-based organizations across multiple industries.

The Hacker News

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • US-based organizations using Fastjson 1. remote code executioN · immediate
  • Security/DevOps teams dependency inventory and workaround rollout · days
  • Alibaba / Fastjson maintainers reputational and patch pressure · weeks

Sources (2)

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — Prism