Remote Code Execution Vulnerability in fastjson by Alibaba
CVE-2026-16723
Key Information:
Badges
What is CVE-2026-16723?
CVE-2026-16723 is a critical vulnerability affecting the fastjson library, a widely used JSON processing tool developed by Alibaba. This vulnerability allows for remote code execution (RCE) within versions 1.2.68 through 1.2.83 of fastjson, posing a serious threat to any organization leveraging this library in their applications. The flaw is particularly concerning because it can be exploited without requiring specific conditions like AutoType enablement or the presence of a classpath gadget, making it accessible under the library's default configuration. This introduces a significant security risk, as attackers could potentially execute arbitrary code on vulnerable systems, leading to unauthorized actions and control over application environments.
Potential impact of CVE-2026-16723
-
Unauthorized Remote Code Execution: Attackers can exploit this vulnerability to run malicious code on affected systems, allowing complete control over the application and the server, which may lead to data breaches or system integrity issues.
-
Compromise of Sensitive Data: With the ability to execute arbitrary code, attackers may access, modify, or exfiltrate sensitive information stored within the application, significantly jeopardizing the organization’s data security and compliance with regulations.
-
Widespread Malware Deployment: This vulnerability could be a gateway for deploying malware, including ransomware, on the affected systems. The ease of exploitation increases the risk of cybercriminals using this flaw to propagate attacks across networks, potentially leading to broader organizational disruptions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fastjson 1.2.68 <= 1.2.83
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
3 weeks ago
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Fastjson 1.x flaw CVE-2026-16723 can trigger unauthenticated RCE in Spring Boot fat-JAR apps, with attacks reported and no patched 1.x fix available.
3 weeks ago
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
