← back

CVE-2026-16723

CRITICAL · 9.0 EPSS 0.4%
hype MIXED · 52 hack

Real vuln, active claims, but absent KEV, PoC, confirmed exploitation metrics.

What: Remote code execution in Alibaba Fastjson 1.2.68–1.2.83 via malicious JSON payloads under default configuration (CVSS 9.0, EPSS 0.34%).

Why it matters: Posts claim active exploitation in Spring Boot applications with no patch available for 1.x branch. Default-enabled RCE without AutoType or gadgets widens attack surface. However, KEV is not listed, and EPSS is extremely low (0.34th percentile), signaling limited real-world traction despite rhetoric.

Where it's seen: Bluesky chatter emphasizes "actively exploited" and "zero-day" framing; posts reference threat intelligence sites and HackerNews. Vendor guidance (SafeMode, migration) is cited but no official patch advisory or PoC confirmation appears in metadata.

RISK: HIGH — CVSS 9.0 RCE, default-enabled, no vendor patch for 1.x. Low EPSS tempers urgency.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/25/2026, 4:33:08 PM

Description

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

CVSS 3.1 breakdown

Exploitability 2.2 · Impact 6.0
vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Complexity
High
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Weaknesses