HackerFeeds

CyberSecurity News

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker News
· July 25, 2026

AI summary

Attackers are targeting a critical vulnerability in Fastjson, a JSON library for Java developed by Alibaba. The flaw allows a malicious JSON request to execute code without authentication in affected Spring Boot applications, running with the privileges of the Java process. The vulnerability has been assigned a CVSS score of 9.0 by Alibaba and is tracked as CVE-2026-16723. A specific exploit chain has been confirmed, taking advantage of this vulnerability.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.