Skip to content
The Nexus
SECURITYJul 25 · 12:52 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva report attackers exploiting a critical Fastjson 1.x vulnerability (CVE-2026-16723) in Spring Boot applications, enabling unauthenticated code execution with Java process privileges. Alibaba's CVSS score of 9.0 highlights the severity, but no patch is currently available.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available · The Nexus