Critical severity9.0NVD Advisory· Published Jul 23, 2026· Updated Jul 23, 2026
CVE-2026-16723
CVE-2026-16723
Description
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.alibaba:fastjsonMaven | >= 1.2.68, <= 1.2.83 | — |
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/advisories/GHSA-crf3-v9rr-v7hjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-16723ghsaADVISORY
News mentions
5- Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based OrganizationsCyber Security News · Jul 28, 2026
- Unpatched Fastjson Vulnerability Exploited in AttacksSecurityWeek · Jul 28, 2026
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawThe Hacker News · Jul 28, 2026
- Hackers target US firms in FastJson RCE zero-day attacksBleepingComputer · Jul 27, 2026
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableThe Hacker News · Jul 25, 2026