EXECUTIVE SUMMARY
A critical remote code execution vulnerability, tracked as CVE-2026-16723 with a CVSS score of 9.0, has been exploited in attacks against Fastjson. This flaw can be leveraged without authentication under the library's default configurations, posing a significant threat to system confidentiality, integrity, and availability. The issue affects Spring Boot executable fat-JAR deployments running the unsupported Fastjson 1.x branch. An attacker who successfully exploits this vulnerability can execute arbitrary code on a target server that has not enabled SafeMode, potentially leading to full server compromise. The attack vector is unauthenticated, making it particularly dangerous because it does not require any form of authentication or authorization to be exploited.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A critical remote code execution vulnerability, tracked as CVE-2026-16723 with a CVSS score of 9.0, has been exploited in attacks against Fastjson. This flaw can be leveraged without authentication under the library's default configurations, posing a significant threat to system confidentiality, integrity, and availability. The issue affects Spring Boot executable fat-JAR deployments running the unsupported Fastjson 1.x branch. An attacker who successfully exploits this vulnerability can execute arbitrary code on a target server that has not enabled SafeMode, potentially leading to full server compromise. The attack vector is unauthenticated, making it particularly dangerous because it does not require any form of authentication or authorization to be exploited.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
[/emaillocker]