Login
← All news

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The Hacker News Security

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain…

Read the full story on The Hacker News https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.