Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek.
Threat actors have been exploiting a critical-severity remote code execution (RCE) vulnerability in Fastjson, security researchers warn.
A popular JSON processing library for Java, Fastjson was developed by Alibaba for JSON serialization and deserialization.
Tracked as CVE-2026-16723 (CVSS score of 9), the unauthenticated bug impacts all deployments running as a Spring Boot executable fat-jar, which is the most widely used deployment model.
Source: https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
Related breach coverage
- Critical Code Execution Vulnerability Patched in TeamCity 2026-07-31
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
- Ruby on Rails Patches Critical Vulnerability2026-08-01
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.
- PTC Windchill Vulnerability Exploited in Ransomware Campaign2026-07-27
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek.
- Exploitation of ServiceNow Vulnerability Seen Days After Disclosure2026-07-21
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.