Remote Code Execution Vulnerability in fastjson by Alibaba
CVE-2026-16723

9CRITICAL

Key Information:

Vendor

Alibaba

Status
Vendor
CVE Published:
23 July 2026

Badges

📈 Score: 314👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-16723?

CVE-2026-16723 is a critical vulnerability affecting the fastjson library, a widely used JSON processing tool developed by Alibaba. This vulnerability allows for remote code execution (RCE) within versions 1.2.68 through 1.2.83 of fastjson, posing a serious threat to any organization leveraging this library in their applications. The flaw is particularly concerning because it can be exploited without requiring specific conditions like AutoType enablement or the presence of a classpath gadget, making it accessible under the library's default configuration. This introduces a significant security risk, as attackers could potentially execute arbitrary code on vulnerable systems, leading to unauthorized actions and control over application environments.

Potential impact of CVE-2026-16723

  1. Unauthorized Remote Code Execution: Attackers can exploit this vulnerability to run malicious code on affected systems, allowing complete control over the application and the server, which may lead to data breaches or system integrity issues.

  2. Compromise of Sensitive Data: With the ability to execute arbitrary code, attackers may access, modify, or exfiltrate sensitive information stored within the application, significantly jeopardizing the organization’s data security and compliance with regulations.

  3. Widespread Malware Deployment: This vulnerability could be a gateway for deploying malware, including ransomware, on the affected systems. The ease of exploitation increases the risk of cybercriminals using this flaw to propagate attacks across networks, potentially leading to broader organizational disruptions.

Affected Version(s)

Fastjson 1.2.68 <= 1.2.83

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.

3 weeks ago

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Fastjson 1.x flaw CVE-2026-16723 can trigger unauthenticated RCE in Spring Boot fat-JAR apps, with attacks reported and no patched 1.x fix available.

3 weeks ago

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kirill Firsov of FearsOff Cybersecurity
.