CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-16723: Critical RCE in Fastjson 1.x

July 25, 2026

A critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for Java, affecting versions 1.2.68 through 1.2.83. The flaw allows unauthenticated attackers to execute arbitrary code on Spring Boot applications via a malicious JSON request. No patch is available as of July 2026.