THE content discusses a critical vulnerability in the FastJson library identified as CVE-2026-16723, which has a CVSS score of 9.0. This Remote Code Execution (RCE) vulnerability affects versions 1.2.68 to 1.2.83 and is actively exploited across various industries including financial services and healthcare. The flaw allows unauthenticated remote attackers to execute code with application privileges through crafted JSON exploiting polymorphic deserialization.
It is confirmed that millions of instances could be affected, urging immediate action as FastJson 1.x is archived with no patched version available. Recommended mitigations include enabling SafeMode and planning migration to FastJson 2.x.