[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:fastjson-1-x-rce-vulnerability-targeted-in-attacks-with-no-patched-available-ms2y05pq":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"074d19a1-6f49-48f6-bda3-8cd08d280201","Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available","fastjson-1-x-rce-vulnerability-targeted-in-attacks-with-no-patched-available-ms2y05pq","Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.","critical","advisory",[12],"CVE-2026-16723",[14,15,16],"Fastjson 1.x","Alibaba","Spring Boot","Immediately inventory all applications using Fastjson 1.x. Enable SafeMode in affected instances or migrate to Fastjson2. Hunt for POST requests with suspicious serialized payloads targeting endpoints known to deserialize user input.",[19],"6e2f2f21-c97a-4e76-bfe0-c3da6b4825e2",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Ffastjson-1x-rce-vulnerability-targeted.html","active","2026-07-29T08:05:56.879+00:00","2026-07-27T08:06:02.355407+00:00","2026-07-27T08:10:07.456931+00:00",[28],{"id":19,"title":6,"url":22}]