INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FastJson RCE Vulnerability Exploit Targeted in Attacks

| 2026-07-27 23:49 CRITICAL HIGH
Executive Summary AI-generated
The recent incident data reveals a critical vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. This zero-day attack has been linked to various organizations across industries, including financial services, healthcare, computing, retail, and business sectors. The malicious activity was observed by security company ThreatBook, with researchers at Imperva confirming that it targeted a wide range of organizations in the US. The vulnerability stems from the library's type-resolution logic, which performs attacker-controlled resource lookups before enforcing AutoType restrictions. This flaw has been identified as CVE-2026-16723 and is currently not being addressed by vendors due to its lack of maintenance.
Technical Mitigations AI-generated
* Enable SafeMode: Organizations can enable SafeMode with the option `-Dfastjson.parser.safeMode=true` or use `com.alibaba:fastjson:1.2.83_noneautotype` to prevent remote code execution attacks. * Use a patched version of FastJson 1.x: Alibaba has not released a fixed version of FastJson 1.x, but organizations can migrate to the latest version (FastJson 1.x) which is considered safe and secure. * Avoid deserialization with malicious payloads: When using Spring Boot fat-JAR deployments, developers should avoid specifying target classes during deserialization or use `Object` or `Map` fields that do not contain malicious payloads. * Use a non-fat-JAR deployment model: Organizations can switch to non-fat-JAR deployments (e.g., `.jar` files) which are less vulnerable to FastJson attacks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-16723CVE-2026-16723
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthcarehealthcare retailretail
Incident Timeline
‎2026/07/20
Threat actors used a FastJson Remote Code Execution (RCE) vulnerability in versions 1.2.68 through 1.2.83 to target US firms across various industries, including Healthcare and Retail.
industry Healthcare
industry Retail
infrastructure 1.2.68
infrastructure 1.2.83
organisation ThreatBook
organisation Financial Services
organisation Computing, Retail, Business
‎July 21
Alibaba's July 21 advisory was published following responsible disclosure by FearsOff Cybersecurity.
organisation FearsOff Cybersecurity
‎July 22
Hackers used a FastJson Remote Code Execution (RCE) vulnerability to target US firms in the incident.
‎July 23
Hackers used a FastJson Remote Code Execution (RCE) vulnerability to target US firms in July 2023.
‎Jul 25, 2026
Threat actors exploited a FastJson RCE zero-day vulnerability to target US firms.
‎July 25
Threat actors used a FastJson Remote Code Execution (RCE) vulnerability to target US firms.
attribution Hacker News
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
organisation The Hacker News
organisation Maven Central repository
‎2026/07/27
Hackers target US firms in FastJson RCE zero-day attacks.
infrastructure 1.2.83
infrastructure 1.2
organisation ThreatBook
organisation Vulnerability / Application Security
organisation FearsOff
organisation CVSS
infrastructure 1.2.60
organisation GitHub
organisation AutoType
organisation fastjson2
organisation Imperva
organisation EDR
organisation Fastjson
organisation JAR
organisation Tomcat
Tactical Metrics
Metrics
infrastructure
‎1.2.68
Software Version
Metrics
infrastructure
‎1.2.83
Software Version
Metrics
infrastructure
‎1.2.60
Software Version
Metrics
infrastructure
‎1.2
Software Version
Intelligence Sources