Dormant High impact Supply chain Checked 3d ago

Hackers exploit unpatched Fastjson zero-day in Java apps

Security researchers reported attackers exploiting a flaw that lets them run code without a login in Java apps using Fastjson 1.2.68 through 1.2.83. Alibaba released Fastjson 1.2.84 with a fix on July 29, 2026. No named victim or confirmed break-in has been made public, and CISA's catalog does not list the flaw as of September 8, 2026.

Started
Jul 20, 2026
Latest activity
Sep 8, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States, Singapore, Canada
Sectors
Finance, Healthcare, Technology, Retail
Scale
financial services, healthcare, computing, and retail organizations, mostly in the US, with smaller volumes in Singapore and Canada

Current status

CISA's September 8 catalog update does not list CVE-2026-16723, and no confirmed attacks, victims, or attribution have been reported since July.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Impact

Attackers sent crafted data requests to internet-facing Spring Boot applications that used a vulnerable Fastjson version. Imperva said most observed traffic came from tools that posed as normal web browsers, while about 30 percent came from scripts written in Ruby and Go. Security vendors reported attack traffic but did not publish evidence of a successful break-in at any named organization.

What to do

IT teams should upgrade Fastjson 1.x to version 1.2.84 or move to Fastjson2 version 2.0.63 or later. Teams that cannot upgrade should turn on SafeMode, use a build with the vulnerable AutoType code removed, and filter known attack requests.

Timeline

  1. Sep 8, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.09.08, does not include CVE-2026-16723. Fresh searches found no new confirmed attacks, named victims, or attribution.

    Dormantcisa.gov
  2. Sep 4, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.09.04, still does not include CVE-2026-16723, checked directly against the live feed. No newer confirmed attacks, named victims, or attribution were found in a fresh web search.

    Activecisa.gov
  3. Sep 2, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.09.02, still does not include CVE-2026-16723, checked directly against the live feed. No newer confirmed attacks, named victims, or attribution were found in a fresh web search.

    Activecisa.gov
  4. Sep 1, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.09.01, does not include CVE-2026-16723, checked directly against the live feed. No newer confirmed attacks, named victims, or attribution were found in a fresh web search.

    Activecisa.gov
  5. Aug 31, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.31, does not include CVE-2026-16723. No newer confirmed attacks, named victims, or attribution were found.

    Activecisa.gov
  6. Aug 27, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.27, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  7. Aug 26, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.26, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  8. Aug 25, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.25, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  9. Aug 24, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.24, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  10. Aug 21, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.21, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  11. Aug 19, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.19, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  12. Aug 18, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.18, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  13. Aug 14, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.14, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  14. Aug 11, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.11, does not include CVE-2026-16723. No newer confirmed attacks, named victims, or attribution were found.

    Activecisa.gov
  15. Aug 10, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.10, does not include CVE-2026-16723.

    Activecisa.gov
  16. Aug 7, 2026

    CISA's Known Exploited Vulnerabilities catalog, version 2026.08.07, still does not include CVE-2026-16723, checked directly against the live feed.

    Activecisa.gov
  17. Jul 28, 2026

    SecurityWeek reported Imperva's finding that about 30 percent of observed attack traffic came from tools written in Ruby and Go, and that with no official patch available, organizations should migrate to Fastjson 2.x or apply SafeMode and request-filtering mitigations.

    Activesecurityweek.com
  18. Jul 27, 2026

    BleepingComputer reported that Fastjson 1.x is no longer actively maintained, so Imperva said it is unlikely to receive a security update, and repeated that developers should enable SafeMode or move off the affected version.

    Activebleepingcomputer.com
  19. Jul 25, 2026

    The Hacker News confirmed no patched Fastjson 1.x release existed and that the flaw remained absent from CISA's Known Exploited Vulnerabilities catalog.

    Activethehackernews.com
  20. Jul 23, 2026

    A CISA-ADP assessment marked exploitation as none, conflicting with vendor reports of observed attacks.

    Activenvd.nist.gov
  21. Jul 22, 2026

    ThreatBook said its platform captured in-the-wild exploitation after adding detection support two days earlier.

    Activethehackernews.com
  22. Jul 21, 2026

    Alibaba published its advisory for CVE-2026-16723 following responsible disclosure by Kirill Firsov of FearsOff Cybersecurity.

    Emergingthehackernews.com

Sources

Related reports