CRITICAL: Fastjson 1.x CVE-2026-16723 Exploited in the Wild With No Patch
Alibaba disclosed a critical remote code execution flaw in Fastjson 1.2.68 through 1.2.83 that works against the library's default configuration, and attackers began exploiting it within a day. CVE-2026-16723 carries a CVSS score of 9.0 and affects Spring Boot applications deployed as executable fat JARs. No patched 1.x release exists, so SafeMode or migration to Fastjson2 is the only real remediation.