Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
What happened
Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability (CVE-2026-16723) in Alibaba's Fastjson 1.x Java library. The flaw allows malicious JSON requests to execute code with the privileges of the Java process, and no patch is currently available.
This legacy edition predates Slugnet’s expanded analytical assessment.