CVE-2026-16723
CRITICAL · 9.0 EPSS 0.4%Real vuln, active claims, but absent KEV, PoC, confirmed exploitation metrics.
What: Remote code execution in Alibaba Fastjson 1.2.68–1.2.83 via malicious JSON payloads under default configuration (CVSS 9.0, EPSS 0.34%).
Why it matters: Posts claim active exploitation in Spring Boot applications with no patch available for 1.x branch. Default-enabled RCE without AutoType or gadgets widens attack surface. However, KEV is not listed, and EPSS is extremely low (0.34th percentile), signaling limited real-world traction despite rhetoric.
Where it's seen: Bluesky chatter emphasizes "actively exploited" and "zero-day" framing; posts reference threat intelligence sites and HackerNews. Vendor guidance (SafeMode, migration) is cited but no official patch advisory or PoC confirmation appears in metadata.
RISK: HIGH — CVSS 9.0 RCE, default-enabled, no vendor patch for 1.x. Low EPSS tempers urgency.
Description
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High