Alibaba disclosed a critical remote code execution flaw, tracked as CVE-2026-16723, in fastjson 1.x versions 1.2.68 through 1.2.83, including the final 1.x release. The vulnerability is exploitable under the library’s default configuration, does not require AutoType to be enabled, and does not depend on a classpath gadget chain. Alibaba said common parsing entry points such as JSON.parse and JSON.parseObject are affected, and that specifying a target DTO class does not reliably block exploitation because attacker-controlled payloads can be embedded in Object- or Map-typed fields.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Alibaba released Fastjson version 1.2.84 to address the remote code execution vulnerability CVE-2026-16723 affecting Fastjson 1.x. The release was presented alongside guidance to upgrade or use mitigations such as SafeMode or the 1.2.83_noneautotype build.
BleepingComputer reported that attackers exploiting CVE-2026-16723 were primarily targeting U.S.-based organizations in financial services, healthcare, computing, retail, and business, with some attacks also observed in Singapore and Canada. The report also noted there was still no patch available and that fastjson 1.x was reportedly no longer actively maintained.
ThreatBook and Imperva reported observing exploitation activity targeting CVE-2026-16723 in the wild. The reports did not provide proof of successful compromise or identify any victims, but they marked the flaw as being actively targeted.
The CVE entry for CVE-2026-16723 was received by Alibaba's CNA and documented the fastjson remote code execution issue affecting versions 1.2.68 through 1.2.83. The record assigned a CVSS v3.1 vector of AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H and mapped the issue to CWE-20 and CWE-502.
FearsOff published research detailing how attacker-controlled @type input can trigger getResourceAsStream, enabling SSRF and, in certain Spring Boot fat-jar deployments, remote class loading leading to code execution. The write-up also described a two-step /proc/self/fd technique to restore RCE on modern JDKs such as JDK 21.
Alibaba published a critical security advisory for a remote code execution vulnerability affecting fastjson versions 1.2.68 through 1.2.83. The advisory said the flaw is exploitable under default configuration in Spring Boot fat-jar deployments and credited Kirill Firsov of FearsOff Cybersecurity with responsible disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcexakep.ru
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcethreatbook.io
Open sourcefearsoff.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.