www.securityweek.com 7/28/2026, 7:57:33 AM · external

Fastjson RCE flaw lets hackers run code on Java servers

Fastjson RCE flaw lets hackers run code on Java servers
Developing story malware 2 articles tracked
Fastjson remote code execution flaw (CVE-2026-16723) exploited in the wild
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical remote code execution (RCE) vulnerability in the Fastjson library (CVE-2026-16723) has been exploited, impacting all versions from 1.2.68 to 1.2.83. Designed for JSON processing in Java, Fastjson allows attackers to execute arbitrary code without authentication, posing risks to server integrity and confidentiality. Exploits have targeted sectors including healthcare and finance, with attacks primarily originating from browser impersonators.

Organizations are advised to upgrade to Fastjson 2.x or implement mitigation measures such as enabling SafeMode. The situation is prioritized for remediation due to the vulnerability’s severe nature.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline