INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FastJson RCE Vulnerability Exploit Targeted in Attacks
| 2026-07-27 23:49 CRITICAL HIGHExecutive Summary AI-generated
The recent incident data reveals a critical vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. This zero-day attack has been linked to various organizations across industries, including financial services, healthcare, computing, retail, and business sectors. The malicious activity was observed by security company ThreatBook, with researchers at Imperva confirming that it targeted a wide range of organizations in the US. The vulnerability stems from the library's type-resolution logic, which performs attacker-controlled resource lookups before enforcing AutoType restrictions. This flaw has been identified as CVE-2026-16723 and is currently not being addressed by vendors due to its lack of maintenance.
Technical Mitigations AI-generated
* Enable SafeMode: Organizations can enable SafeMode with the option `-Dfastjson.parser.safeMode=true` or use `com.alibaba:fastjson:1.2.83_noneautotype` to prevent remote code execution attacks.
* Use a patched version of FastJson 1.x: Alibaba has not released a fixed version of FastJson 1.x, but organizations can migrate to the latest version (FastJson 1.x) which is considered safe and secure.
* Avoid deserialization with malicious payloads: When using Spring Boot fat-JAR deployments, developers should avoid specifying target classes during deserialization or use `Object` or `Map` fields that do not contain malicious payloads.
* Use a non-fat-JAR deployment model: Organizations can switch to non-fat-JAR deployments (e.g., `.jar` files) which are less vulnerable to FastJson attacks.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-16723CVE-2026-16723
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthcarehealthcare
retailretail
Incident Timeline
2026/07/20
Threat actors used a FastJson Remote Code Execution (RCE) vulnerability in versions 1.2.68 through 1.2.83 to target US firms across various industries, including Healthcare and Retail.
Click on any entity below to view its context and source!
industry
Healthcare
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
industry
Retail
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
infrastructure
1.2.68
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
infrastructure
1.2.83
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
organisation
ThreatBook
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
organisation
Financial Services
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
organisation
Computing, Retail, Business
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
July 21
Alibaba's July 21 advisory was published following responsible disclosure by FearsOff Cybersecurity.
Click on any entity below to view its context and source!
organisation
FearsOff Cybersecurity
Alibaba
published its advisory
on July 21 following responsible disclosure by
Kirill Firsov
of FearsOff Cybersecurity.
July 22
Hackers used a FastJson Remote Code Execution (RCE) vulnerability to target US firms in the incident.
July 23
Hackers used a FastJson Remote Code Execution (RCE) vulnerability to target US firms in July 2023.
Jul 25, 2026
Threat actors exploited a FastJson RCE zero-day vulnerability to target US firms.
July 25
Threat actors used a FastJson Remote Code Execution (RCE) vulnerability to target US firms.
Click on any entity below to view its context and source!
attribution
Hacker News
The Hacker News confirmed on July 25 that the flaw was absent from CISA's current
Known Exploited Vulnerabilities catalog
.
attribution
Known Exploited
The Hacker News confirmed on July 25 that the flaw was absent from CISA's current
Known Exploited Vulnerabilities catalog
.
tactic
T1588.006 - Vulnerabilities
The Hacker News confirmed on July 25 that the flaw was absent from CISA's current
Known Exploited Vulnerabilities catalog
.
organisation
The Hacker News
The Hacker News also found no patched Fastjson 1.x artifact in the project's
GitHub tags
or
Maven Central repository
as of July 25.
organisation
Maven Central repository
The Hacker News also found no patched Fastjson 1.x artifact in the project's
GitHub tags
or
Maven Central repository
as of July 25.
2026/07/27
Hackers target US firms in FastJson RCE zero-day attacks.
Click on any entity below to view its context and source!
infrastructure
1.2.83
Version 1.2.83 remains the latest standard 1.x release, while
1.2.83_noneautotype
remains the available restricted build.
infrastructure
1.2
Version 1.2.83 remains the latest standard 1.x release, while
1.2.83_noneautotype
remains the available restricted build.
organisation
ThreatBook
Swati Khandelwal
Jul 25, 2026
Vulnerability / Application Security
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java.
organisation
Vulnerability / Application Security
Swati Khandelwal
Jul 25, 2026
Vulnerability / Application Security
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java.
organisation
FearsOff
CVE-2026-16723 was discovered by FearsOff, an offensive security company, which published a
technical write-up
earlier this month.
organisation
CVSS
Tracked as
CVE-2026-16723
, the vulnerability carries an Alibaba-assigned CVSS score of 9.0.
infrastructure
1.2.60
Also, FastJson versions 1.2.60 and earlier, and any non-fat-JAR deployments, aren’t affected either.
organisation
GitHub
The project has 25,600 stars and 6,400 forks on GitHub, and is especially prevalent in Chinese enterprise software and projects built on Alibaba's platform.
organisation
AutoType
The researchers explain that the flaw stems from the library’s type-resolution logic, which performs attacker-controlled resource lookups before enforcing AutoType restrictions.
AutoType can remain disabled, and no classpath gadget is required.
organisation
fastjson2
The vulnerable type-resolution logic is not present in fastjson2, which uses an allowlist-first model for polymorphic deserialization and doesn’t rely on the @JSONType annotation as a trust signal.
organisation
Imperva
Imperva has also noted that FastJson 1.x is no longer actively maintained, so it’s unlikely it will receive a security update.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
Fastjson
Firsov traced the issue to Fastjson's type-resolution path.
organisation
JAR
His
technical analysis
also describes a newer-JDK path that downloads a remote JAR and references it through
/proc/self/fd
.
organisation
Tomcat
Alibaba lists plain non-fat JARs, generic uber-JARs, and Tomcat or Jetty WAR deployments as unaffected.
Tactical Metrics
Metrics
infrastructure
1.2.68
Software Version
Click for context!
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
Metrics
infrastructure
1.2.83
Software Version
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was
observed last week
by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.
Version 1.2.83 remains the latest standard 1.x release, while
1.2.83_noneautotype
remains the available restricted build.
Metrics
infrastructure
1.2.60
Software Version
Also, FastJson versions 1.2.60 and earlier, and any non-fat-JAR deployments, aren’t affected either.
Metrics
infrastructure
1.2
Software Version
Version 1.2.83 remains the latest standard 1.x release, while
1.2.83_noneautotype
remains the available restricted build.
Intelligence Sources
The Hacker News
2026-07-25
BleepingComputer
2026-07-27
Hackers target US firms in FastJson RCE zero-day attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-28T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
ThreatBook
entity
9x
timeline
Temporal Reference
2026/07/20
date
4x
target region
Target Country
United States
country
4x
infrastructure
Software Version
1.2.68
version
3x
general metric
%
54
%
2x
industry
Targeted Sector
Healthcare
sector
2x
general metric
Jdk
21
jdk
2x
attribution
Attributing Entity
Hacker News
authority
Contextual Telemetry
Context Block
7 METRICS
tactic
Cyber Operation Type
Remote Code Execution
tactic
vulnerability
Exploited CVE
CVE-2026-16723
cve
general metric
Stars
25,600
stars
general metric
Forks
6,400
forks
vulnerability
CVSS Score
9
score
general metric
Khandelwal Jul
25
khandelwal jul
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.