a critical bug in one of Java's most-used libraries had no fix. that just changed

Hackers were already exploiting Fastjson's default config for over a week before Alibaba's patch quietly showed up on a wiki page.

Aliteq
Priya Nair · Software & Systems Editor

The situation as of today

CVE-2026-16723 is a critical (CVSS 9.0) unauthenticated RCE in Fastjson 1.2.68 through 1.2.83 — no AutoType enabling and no gadget chain required, just Fastjson's stock default config plus a Spring…

The situation as of today

It was responsibly disclosed by security researcher Kirill Firsov of FearsOff, who verified it against Spring Boot 2.x, 3.x and 4.x on JDK 8, 11, 17 and 21.

The situation as of today

ThreatBook and Imperva confirmed active exploitation in the wild, hitting financial services, healthcare, computing and retail organizations mostly in the US, with smaller activity in Singapore and…

The situation as of today

Alibaba released fastjson 1.2.84 on July 29, 2026 — after the bulk of 'no fix available' reporting had already gone out.

The situation as of today

If you can't upgrade today, enable SafeMode (-Dfastjson.parser.safeMode=true) — it blocks the vulnerable path even on the old, unpatched builds.

The situation as of today

Fastjson2 was never affected by this bug.

Aliteq

Read the full story

a critical bug in one of Java's most-used libraries had no fix. that just changed

Read the full story on Aliteq