AI description
CVE-2026-16723 identifies a remote code execution (RCE) vulnerability affecting Alibaba's Fastjson library, specifically versions 1.2.68 through 1.2.83. This flaw allows for exploitation under Fastjson's default configuration, meaning it does not require the `AutoType` feature to be enabled or the presence of specific classpath gadgets. The vulnerability is particularly concerning in Spring Boot applications deployed as executable fat-JARs across various JDK versions, including 8, 11, 17, and 21. The vulnerability stems from the library's type-resolution mechanism. An attacker can craft a malicious JSON payload containing a specially designed `@type` value. This crafted input can lead Fastjson to perform resource lookups that allow an attacker to introduce and execute controlled bytecode from a nested JAR path within compatible Spring Boot deployments. The `@JSONType` annotation on the malicious resource then bypasses Fastjson's security checks, facilitating the code execution. Alibaba published an advisory on July 21, 2026, and has recommended enabling SafeMode, using a restricted build, or migrating to Fastjson2 as mitigation, as no patch for the 1.x branch is available.
- Description
- A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
- Source
- alibaba-cna@list.alibaba-inc.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- alibaba-cna@list.alibaba-inc.com
- CWE-20
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9
FastJsonのRCE脆弱性CVE-2026-16723が実際に悪用され、詳細とPoCエクスプロイトコードが公開された FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public #DailyCyberSecurity (Jul 25) https://t.co/cc7NU7T3wx
@foxbook
27 Jul 2026
267 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ Not every CVE should produce every detection rule. For Fastjson CVE-2026-16723, current public evidence supports exposure triage—not a reliable standalone Sigma or YARA rule. Validate versions, fat-JAR deployment, and SafeMode first. https://t.co/5kSkgnnNuF
@supernovanomad
26 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-16723: Active Exploitation of Fast 1.x RCE in Spring Boot — Defense an… "Security teams must immediately heighten defenses around Java-based web applications." 🔗 https://t.co/8VT8DdqpKh #CyberSecurity #ThreatIntel #critical #zeroday #cve
@SecurityAr58409
25 Jul 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-16723: A critical FastJson RCE vulnerability is being actively exploited in the wild. Public technical details and a PoC are now available. 🔗 https://t.co/GevinKhEY1 #FastJson #RCE #CVE #CyberSecurity https://t.co/jtbo8dLqLE
@ThreatWire_
25 Jul 2026
4339 Impressions
15 Retweets
49 Likes
24 Bookmarks
0 Replies
0 Quotes