Vulnerability report

Active exploitation observed Confirmed confidence Not in CISA KEV

CVE-2026-16723

Remote Code Execution in fastjson 1.2.68–1.2.83

Alibaba / Fastjson · 1.2.68 to <= 1.2.83

Severity
CVSS 9.0 · Critical
Confidence
Confirmed
Exploit status
Observed in sensors
EPSS
0.4%
First observed
27 Jul 2026
Last observed
27 Jul 2026

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-16723 is an unauthenticated Remote Code Execution in fastjson 1.2.68–1.2.83. A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under...

Is it exploited?

Yes. KEV Intelligence sensors observed exploitation attempts with confirmed confidence.

Who is affected?

Alibaba / Fastjson 1.2.68 to <= 1.2.83.

What should we do?

Patch immediately, validate internet-facing exposure, and monitor for matching requests.

Overview

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83.

This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Vendor Product Affected Status
Alibaba Fastjson Through 1.2.83 Affected
View vendor advisory (opens in new tab)
Published
23 Jul 2026
Exploitation Reported
25 Jul 2026
Attack vector
Remote
Complexity
High
Privileges
None
User interaction
None

CVE References

Exploitation evidence

Why KEV Intelligence marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Daily CyberSecurity

Recorded 25 Jul 2026

Independent exploitation attestation added to the KEV Intelligence record.

Active exploitation observed

KEV Intelligence sensor

First observed 27 Jul 2026

First-party sensor telemetry confirms matching exploitation attempts.

Proof of concept available

GitHub

Recorded 25 Jul 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.

Learn about Pro API access
Source Added
Daily CyberSecurity First 2026-07-25 02:23 UTC
KEV Intelligence 2026-07-27 01:40 UTC

Operational indicators for this CVE are listed under Detection.

Sensor telemetry

First-party evidence of exploitation activity

Aggregate observations show the scale, recency, and distribution of activity without overstating sparse data.

192

Attempts observed

1

Unique attacker IPs

1

Attacker countries

BG

2

Sensors observed

Exploitation attempts over the last 25 days

Daily events observed by KEV Intelligence sensors

Updated 19 Aug 2026

0
192
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
26 Jul 31 Jul 5 Aug 10 Aug 19 Aug

First observed 27 Jul 2026 · Last observed 27 Jul 2026

Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.

Request telemetry access

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
48
User-Agents
1

Raw values available in Pro and Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

Attacker IP Indicators

Attacker IP indicators observed · available in Pro and Enterprise.

Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.

Learn about Pro API access

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.0 Critical
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.4%

Recent mention · TheHackerNews

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java...

Read full advisory

All Mentions

Recent mention · TheHackerNews

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

TheHackerNews · 25 Jul 2026

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires

Recent mention · Daily CyberSecurity

FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public

Daily CyberSecurity · 25 Jul 2026

TL;DR A critical FastJson RCE vulnerability, CVE-2026-16723, carries a CVSS score of 9.0. Full technical details and working The post FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public appeared first on Daily CyberSecurity.

Recent mention · Imperva

Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE

Imperva · 24 Jul 2026

TL;DR: A critical remote code execution vulnerability has been disclosed in FastJson, a widely used JSON processing library for Java. The vulnerability, assigned CVE-2026-16723 with a CVSS score of 9.0 (Critical), affects FastJson versions 1.2.68 through 1.2.83 under specific Spring Boot deployment conditions and can be exploited using malicious JSON without authentication, enabling AutoType, or relying on third-party gadget classes.  Imperva customers are protected against exploitation attempts […] The post Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day...

Recent mention · Daily CyberSecurity

CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM

Daily CyberSecurity · 24 Jul 2026

A public proof-of-concept details the Windows AppResolver LPE (CVE-2026-50454), a UAC bypass that chains an admin token to a SYSTEM shell. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 The post CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM appeared first on Daily CyberSecurity.

Recent mention · Daily CyberSecurity

Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic

Daily CyberSecurity · 24 Jul 2026

A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 The post Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic appeared first on Daily CyberSecurity.

Recent mention · Daily CyberSecurity

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

Daily CyberSecurity · 24 Jul 2026

CVE-2026-61884 is a Tycon authentication bypass rated CVSS 9.8 in TPDIN-Monitor-WEB2. No vendor fix exists, so isolate the devices now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 appeared first on Daily CyberSecurity.

Recent mention · Daily CyberSecurity

ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10

Daily CyberSecurity · 24 Jul 2026

ManageEngine fixed an ADAudit Plus vulnerability, CVE-2026-6516, a CVSS 10 unauthenticated remote code execution flaw. Update to build 8606 now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10 appeared first on Daily CyberSecurity.

Recent mention · Daily CyberSecurity

Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw

Daily CyberSecurity · 24 Jul 2026

Researchers publicly disclosed a Knot Resolver RCE flaw and PoC exploit code. The DNS-over-QUIC heap overflow hits 6.3.0; update to 6.4.1 now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw appeared first on Daily CyberSecurity.

Recent mention · Daily CyberSecurity

CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling

Daily CyberSecurity · 24 Jul 2026

CERT/CC discloses six Logto vulnerabilities, including CVE-2026-15611 and CVE-2026-15616, that enable SSO authentication bypass and MFA skipping. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling appeared first on Daily CyberSecurity.

Recent mention · Daily CyberSecurity

Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs

Daily CyberSecurity · 24 Jul 2026

Google's Chrome security update fixes four high-severity bugs, including CVE-2026-16807, a Codecs flaw that could enable a sandbox escape. Update now. Related Posts: FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic The post Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs appeared first on Daily CyberSecurity.

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Superman-L/CVE-2026-16723

github · Created 2026-08-19 05:01:42 UTC · 0 stars · AI assessment 85%

fastjson jsontype利用

Timeline

From disclosure to observed exploitation

  1. Public PoC available

    Public proof-of-concept code published

  2. Observed by KEV Intelligence sensors

    Evidence-backed exploitation signal

  3. Indicator of compromise added

    Indicators of compromise recorded

  4. Added to KEV Intelligence KEV Feed

    High-confidence, third-party attested exploitation

  5. CVE published

    Vulnerability disclosed publicly

  6. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-16723

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-16723",
  "confidence": "Confirmed",
  "cvss_score": 9.0,
  "cvss_estimated": false,
  "epss_score": 0.00413,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": true
  },
  "sensor_telemetry": { "attempts": 192, "sensors": 2 }
}

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.