CVE-2026-16723
CVSS 9 CRITICAL: a remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. EPSS 0.7% (50º percentile).
Vulnerabilità ed exploit
L'assunto che "AutoType disattivato" basti a mettere in sicurezza Fastjson è falso nei deployment Spring Boot fat-JAR. In quelle applicazioni, un JSON raggiungibile da rete può ancora trasformarsi in codice eseguito con i privilegi del processo Java, anche senza autenticazione e senza bisogno di un gadget di classpath.
ThreatBook e Imperva riferiscono sfruttamento in corso di CVE-2026-16723 su Fastjson 1.2.68–1.2.83. Alibaba ha confermato il problema con CVSS 9.0, ma al 25 luglio non aveva ancora pubblicato una correzione per la linea 1.x; i fix temporanei indicati sono SafeMode con -Dfastjson.parser.safeMode=true oppure fastjson:1.2.83_noneautotype, in attesa della migrazione a Fastjson2.
Per chi gestisce servizi Java esposti, il punto non è la sola versione vulnerabile: è il modello di fiducia del parser, che in un fat-JAR può trattare il dato come istruzione di caricamento. Se l'endpoint JSON resta raggiungibile, il rischio non è una semplice deserializzazione errata ma un path diretto verso RCE non autenticata.
3 fonti · 28 lug
CVSS 9 CRITICAL: a remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. EPSS 0.7% (50º percentile).
SecurityWeek
Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.
originaleBleepingComputer
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
originaleThe Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Fastjson 1.x flaw CVE-2026-16723 can trigger unauthenticated RCE in Spring Boot fat-JAR apps, with attacks reported and no patched 1.x fix available.
originalePart of the PlainSec briefing for 2026-07-27
Every edition of this story: Fastjson espone i fat-JAR Spring Boot a RCE senza autenticazione