SECURITYTHE HACKER NEWS
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva report attackers exploiting a critical Fastjson 1.x vulnerability (CVE-2026-16723) in Spring Boot applications, enabling unauthenticated code execution with Java process privileges. Alibaba's CVSS score of 9.0 highlights the severity, but no patch is currently available.
Mentioned
Related Signal
Adjacent reporting
- Max severity Flowise RCE vulnerability now exploited in attacks
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown
- F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
- NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE