DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-16723PUBLISHED: 2026-07-21
CRITICALCVE-2026-16723

Alibaba Fastjson 1.x Zero-Day Unauthenticated RCE — No Patch Available

VENDOR: Alibaba//PRODUCT: Fastjson
9
CRITICAL
CVSS 3.1
NO PATCH AVAILABLE
This vulnerability has no vendor patch at this time. Apply mitigation steps below or restrict network access to affected systems.
PATCH STATUS
NO PATCH
EXPLOIT STATUS
PUBLIC EXPLOIT

A critical zero-day RCE (CVSS 9.0) in Alibaba Fastjson 1.x allows unauthenticated attackers to execute arbitrary code via a crafted JSON request targeting Spring Boot fat-JAR deployments under default configuration — no AutoType enablement, no classpath gadget, and no user interaction required. ThreatBook first observed active exploitation in the wild; Imperva confirmed attack campaigns targeting U.S. financial services, healthcare, retail, and computing organizations. No patched 1.x version exists and none is expected, as Fastjson 1.x is end-of-life; mitigate immediately by enabling SafeMode or migrating to Fastjson 2.x.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSFastjson versions 1.2.68 through 1.2.83 running as Spring Boot executable fat-JAR; Fastjson 2.x not affected
  • https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
  • https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
  • https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/
  • https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn