VULNERABILITY OVERVIEW
A critical zero-day RCE (CVSS 9.0) in Alibaba Fastjson 1.x allows unauthenticated attackers to execute arbitrary code via a crafted JSON request targeting Spring Boot fat-JAR deployments under default configuration — no AutoType enablement, no classpath gadget, and no user interaction required. ThreatBook first observed active exploitation in the wild; Imperva confirmed attack campaigns targeting U.S. financial services, healthcare, retail, and computing organizations. No patched 1.x version exists and none is expected, as Fastjson 1.x is end-of-life; mitigate immediately by enabling SafeMode or migrating to Fastjson 2.x.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
Fastjson versions 1.2.68 through 1.2.83 running as Spring Boot executable fat-JAR; Fastjson 2.x not affectedCITATIONS
- → https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
- → https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
- → https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/
- → https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/