INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FastJson RCE Vulnerability Exploit Targeted in Attacks

| 2026-07-27 23:49 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent incident data reveals a critical vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. This zero-day attack has been linked to various organizations across industries, including financial services, healthcare, computing, retail, and business sectors. The malicious activity was observed by security company ThreatBook, with researchers at Imperva confirming that it targeted a wide range of organizations in the US. The vulnerability stems from the library's type-resolution logic, which performs attacker-controlled resource lookups before enforcing AutoType restrictions. This flaw has been identified as CVE-2026-16723 and is currently not being addressed by vendors due to its lack of maintenance.
Technical Mitigations AI-generated
* Enable SafeMode: Organizations can enable SafeMode with the option `-<a href="/auth/login?next=/detail/rnf0nJ8BCQgLW4qe3Q1A" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>=true` or use `<a href="/auth/login?next=/detail/rnf0nJ8BCQgLW4qe3Q1A" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>:fastjson:1.2.83_noneautotype` to prevent remote code execution attacks. * Use a patched version of FastJson 1.x: Alibaba has not released a fixed version of FastJson 1.x, but organizations can migrate to the latest version (FastJson 1.x) which is considered safe and secure. * Avoid deserialization with malicious payloads: When using Spring Boot fat-JAR deployments, developers should avoid specifying target classes during deserialization or use `Object` or `Map` fields that do not contain malicious payloads. * Use a non-fat-JAR deployment model: Organizations can switch to non-fat-JAR deployments (e.g., `.jar` files) which are less vulnerable to FastJson attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

js•••••.parseobject
xx•••••.jar
co•••••.alibaba
js•••••.parse
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-16723CVE-2026-16723
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance healthhealth retailretail
Incident Timeline
‎2026/07/20
Threat actors used a FastJson Remote Code Execution (RCE) vulnerability in versions 1.2.68 through 1.2.83 to target US firms across various industries, including Healthcare and Retail.
industry Healthcare
industry Retail
infrastructure 1.2.68
infrastructure 1.2.83
organisation ThreatBook
organisation Financial Services
organisation Computing, Retail, Business
‎July 21
Alibaba's July 21 advisory was published following responsible disclosure by FearsOff Cybersecurity.
organisation FearsOff Cybersecurity
‎July 22
Hackers used a FastJson Remote Code Execution (RCE) vulnerability to target US firms in the incident.
‎July 23
Hackers used a FastJson Remote Code Execution (RCE) vulnerability to target US firms in July 2023.
‎Jul 25, 2026
Threat actors exploited a FastJson RCE zero-day vulnerability to target US firms.
‎July 25
Threat actors used a FastJson Remote Code Execution (RCE) vulnerability to target US firms.
attribution Hacker News
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
organisation The Hacker News
organisation Maven Central repository
‎2026/07/27
Hackers target US firms in FastJson RCE zero-day attacks.
infrastructure 1.2.83
infrastructure 1.2
organisation ThreatBook
organisation Vulnerability / Application Security
organisation FearsOff
organisation CVSS
infrastructure 1.2.60
organisation GitHub
organisation AutoType
organisation fastjson2
organisation Imperva
organisation EDR
organisation Fastjson
organisation JAR
organisation Tomcat
Tactical Metrics
Metrics
infrastructure
‎1.2.68
Software Version
Metrics
infrastructure
‎1.2.83
Software Version
Metrics
infrastructure
‎1.2.60
Software Version
Metrics
infrastructure
‎1.2
Software Version
Intelligence Sources