Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
What happened
Attackers are actively exploiting CVE-2026-16723, a critical unauthenticated remote code execution flaw in Alibaba's Fastjson library for Java. In affected Spring Boot applications, malicious JSON requests can execute code with the privileges of the Java process.
This legacy edition predates Slugnet’s expanded analytical assessment.