Back to advisories

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.

CRITICALAdvisoryJul 27, 2026
Action required
Immediately inventory all applications using Fastjson 1.x. Enable SafeMode in affected instances or migrate to Fastjson2. Hunt for POST requests with suspicious serialized payloads targeting endpoints known to deserialize user input.
Affected products
Fastjson 1.xAlibabaSpring Boot