CVE-2026-16723
High PUBLISHEDRemote Code Execution in fastjson 1.2.68–1.2.83
Not yet in CISA KEV
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
- CVE Published
- Jul 23, 2026
- Exploitation Reported
- Jul 25, 2026
- CVSS
- 9.0 Critical
- EPSS
- 0.4%
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| Alibaba |
Fastjson
|
1.2.68 to <= 1.2.83 |
Affected |
CVE References
- GitHub — alibaba/fastjson2 github.com · Vendor Advisory https://github.com/alibaba/fastjson2/wiki/Security-Advisory:-Remote-C...
- Fastjson @JSONType remote-JAR/FD-chain lab and detection Analysis https://github.com/dinosn/fastjson-jsontype-rce-lab
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Daily CyberSecurity First | 2026-07-25 02:23 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2026-07-25 02:23:23 UTC · Daily CyberSecurity
Recent Mentions
TheHackerNews · Jul 25, 2026
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires
Daily CyberSecurity · Jul 25, 2026
TL;DR A critical FastJson RCE vulnerability, CVE-2026-16723, carries a CVSS score of 9.0. Full technical details and working The post FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public appeared first on Daily CyberSecurity.
Imperva · Jul 24, 2026
TL;DR: A critical remote code execution vulnerability has been disclosed in FastJson, a widely used JSON processing library for Java. The vulnerability, assigned CVE-2026-16723 with a CVSS score of 9.0 (Critical), affects FastJson versions 1.2.68 through 1.2.83 under specific Spring Boot deployment conditions and can be exploited using malicious JSON without authentication, enabling AutoType, or relying on third-party gadget classes. Imperva customers are protected against exploitation attempts […] The post Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE appeared first on Blog.
Daily CyberSecurity · Jul 24, 2026
A public proof-of-concept details the Windows AppResolver LPE (CVE-2026-50454), a UAC bypass that chains an admin token to a SYSTEM shell. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 The post CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM appeared first on Daily CyberSecurity.
Daily CyberSecurity · Jul 24, 2026
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 The post Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic appeared first on Daily CyberSecurity.
Daily CyberSecurity · Jul 24, 2026
CVE-2026-61884 is a Tycon authentication bypass rated CVSS 9.8 in TPDIN-Monitor-WEB2. No vendor fix exists, so isolate the devices now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 appeared first on Daily CyberSecurity.
Daily CyberSecurity · Jul 24, 2026
ManageEngine fixed an ADAudit Plus vulnerability, CVE-2026-6516, a CVSS 10 unauthenticated remote code execution flaw. Update to build 8606 now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10 appeared first on Daily CyberSecurity.
Daily CyberSecurity · Jul 24, 2026
Researchers publicly disclosed a Knot Resolver RCE flaw and PoC exploit code. The DNS-over-QUIC heap overflow hits 6.3.0; update to 6.4.1 now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw appeared first on Daily CyberSecurity.
Daily CyberSecurity · Jul 24, 2026
CERT/CC discloses six Logto vulnerabilities, including CVE-2026-15611 and CVE-2026-15616, that enable SSO authentication bypass and MFA skipping. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling appeared first on Daily CyberSecurity.
Daily CyberSecurity · Jul 24, 2026
Google's Chrome security update fixes four high-severity bugs, including CVE-2026-16807, a Codecs flaw that could enable a sandbox escape. Update now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs appeared first on Daily CyberSecurity.
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
02:23 UTC about 13 hours ago02:23 UTC · about 13 hours ago
Added to KEVIntel KEV Feed
High-confidence, third-party attested exploitation
-
08:26 UTC 2 days ago08:26 UTC · 2 days ago
CVE published
Vulnerability disclosed publicly
-
02:40 UTC 3 days ago02:40 UTC · 3 days ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2026-16723
{
"cve_id": "CVE-2026-16723",
"title": "Remote Code Execution in fastjson 1.2.68–1.2.83",
"affected_vendor": "Alibaba",
"affected_product": "Fastjson",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "High",
"cvss_score": 9.0,
"epss_score": 0.00413,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}