Back to advisories

Hackers target US firms in FastJson RCE zero-day attacks

A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.

CRITICALAdvisoryJul 29, 2026
Action required
Immediately inventory all applications using FastJson 1.2.68-1.2.83. Enable SafeMode as emergency mitigation or upgrade to fastjson2. Hunt for exploitation indicators in application logs and network traffic.
Affected products
FastJsonAlibabafastjson2