DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-16723PUBLISHED: 2026-07-21
■ CRITICALCVE-2026-16723

Alibaba Fastjson 1.x Zero-Day Unauthenticated RCE — No Patch Available

VENDOR: Alibaba//PRODUCT: Fastjson
9
CRITICAL
CVSS 3.1
⚠
NO PATCH AVAILABLE
This vulnerability has no vendor patch at this time. Apply mitigation steps below or restrict network access to affected systems.
✗
PATCH STATUS
NO PATCH
⚡
EXPLOIT STATUS
PUBLIC EXPLOIT

A critical zero-day RCE (CVSS 9.0) in Alibaba Fastjson 1.x allows unauthenticated attackers to execute arbitrary code via a crafted JSON request targeting Spring Boot fat-JAR deployments under default configuration — no AutoType enablement, no classpath gadget, and no user interaction required. ThreatBook first observed active exploitation in the wild; Imperva confirmed attack campaigns targeting U.S. financial services, healthcare, retail, and computing organizations. No patched 1.x version exists and none is expected, as Fastjson 1.x is end-of-life; mitigate immediately by enabling SafeMode or migrating to Fastjson 2.x.

↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSFastjson versions 1.2.68 through 1.2.83 running as Spring Boot executable fat-JAR; Fastjson 2.x not affected
  • → https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
  • → https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
  • → https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/
  • → https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn