Dossier
Fastjson
Coverage of Fastjson in the Nexus archive.
- Hackers target US firms in FastJson RCE zero-day attacks
Hackers are exploiting a vulnerability in the FastJson open-source Java library to launch remote code execution (RCE) attacks against US firms. The attacks allow remote code execution without requiring user interaction or elevated privileges.
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva report attackers exploiting a critical Fastjson 1.x vulnerability (CVE-2026-16723) in Spring Boot applications, enabling unauthenticated code execution with Java process privileges. Alibaba's CVSS score of 9.0 highlights the severity, but no patch is currently available.