A critical remote code execution (RCE) vulnerability in the Fastjson library (CVE-2026-16723) has been exploited, impacting all versions from 1.2.68 to 1.2.83. Designed for JSON processing in Java, Fastjson allows attackers to execute arbitrary code without authentication, posing risks to server integrity and confidentiality. Exploits have targeted sectors including healthcare and finance, with attacks primarily originating from browser impersonators.
Organizations are advised to upgrade to Fastjson 2.x or implement mitigation measures such as enabling SafeMode. The situation is prioritized for remediation due to the vulnerability’s severe nature.