securityonline.info 7/25/2026, 4:50:50 AM · external

Urgent FastJson RCE flaw CVE-2026-16723 hits finance and health

Urgent FastJson RCE flaw CVE-2026-16723 hits finance and health
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE content discusses a critical vulnerability in the FastJson library identified as CVE-2026-16723, which has a CVSS score of 9.0. This Remote Code Execution (RCE) vulnerability affects versions 1.2.68 to 1.2.83 and is actively exploited across various industries including financial services and healthcare. The flaw allows unauthenticated remote attackers to execute code with application privileges through crafted JSON exploiting polymorphic deserialization.

It is confirmed that millions of instances could be affected, urging immediate action as FastJson 1.x is archived with no patched version available. Recommended mitigations include enabling SafeMode and planning migration to FastJson 2.x.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline