CyberSecurity News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
AI summary
Attackers are targeting a critical vulnerability in Fastjson, a JSON library for Java developed by Alibaba. The flaw allows a malicious JSON request to execute code without authentication in affected Spring Boot applications, running with the privileges of the Java process. The vulnerability has been assigned a CVSS score of 9.0 by Alibaba and is tracked as CVE-2026-16723. A specific exploit chain has been confirmed, taking advantage of this vulnerability.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

