Hackers exploit unpatched Fastjson zero-day in Java apps
Security researchers reported attackers exploiting a flaw that lets them run code without a login in Java apps using Fastjson 1.2.68 through 1.2.83. Alibaba released Fastjson 1.2.84 with a fix on July 29, 2026. No named victim or confirmed break-in has been made public, and CISA's catalog does not list the flaw as of September 8, 2026.
- Started
- Jul 20, 2026
- Latest activity
- Sep 8, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States, Singapore, Canada
- Sectors
- Finance, Healthcare, Technology, Retail
- Scale
- financial services, healthcare, computing, and retail organizations, mostly in the US, with smaller volumes in Singapore and Canada
Current status
CISA's September 8 catalog update does not list CVE-2026-16723, and no confirmed attacks, victims, or attribution have been reported since July.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Impact
Attackers sent crafted data requests to internet-facing Spring Boot applications that used a vulnerable Fastjson version. Imperva said most observed traffic came from tools that posed as normal web browsers, while about 30 percent came from scripts written in Ruby and Go. Security vendors reported attack traffic but did not publish evidence of a successful break-in at any named organization.
What to do
IT teams should upgrade Fastjson 1.x to version 1.2.84 or move to Fastjson2 version 2.0.63 or later. Teams that cannot upgrade should turn on SafeMode, use a build with the vulnerable AutoType code removed, and filter known attack requests.
Timeline
-
Sep 8, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.09.08, does not include CVE-2026-16723. Fresh searches found no new confirmed attacks, named victims, or attribution.
Dormantcisa.gov -
Sep 4, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.09.04, still does not include CVE-2026-16723, checked directly against the live feed. No newer confirmed attacks, named victims, or attribution were found in a fresh web search.
Activecisa.gov -
Sep 2, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.09.02, still does not include CVE-2026-16723, checked directly against the live feed. No newer confirmed attacks, named victims, or attribution were found in a fresh web search.
Activecisa.gov -
Sep 1, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.09.01, does not include CVE-2026-16723, checked directly against the live feed. No newer confirmed attacks, named victims, or attribution were found in a fresh web search.
Activecisa.gov -
Aug 31, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.31, does not include CVE-2026-16723. No newer confirmed attacks, named victims, or attribution were found.
Activecisa.gov -
Aug 27, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.27, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 26, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.26, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 25, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.25, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 24, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.24, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 21, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.21, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 19, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.19, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 18, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.18, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 14, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.14, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Aug 11, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.11, does not include CVE-2026-16723. No newer confirmed attacks, named victims, or attribution were found.
Activecisa.gov -
Aug 10, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.10, does not include CVE-2026-16723.
Activecisa.gov -
Aug 7, 2026
CISA's Known Exploited Vulnerabilities catalog, version 2026.08.07, still does not include CVE-2026-16723, checked directly against the live feed.
Activecisa.gov -
Jul 28, 2026
SecurityWeek reported Imperva's finding that about 30 percent of observed attack traffic came from tools written in Ruby and Go, and that with no official patch available, organizations should migrate to Fastjson 2.x or apply SafeMode and request-filtering mitigations.
Activesecurityweek.com -
Jul 27, 2026
BleepingComputer reported that Fastjson 1.x is no longer actively maintained, so Imperva said it is unlikely to receive a security update, and repeated that developers should enable SafeMode or move off the affected version.
Activebleepingcomputer.com -
Jul 25, 2026
The Hacker News confirmed no patched Fastjson 1.x release existed and that the flaw remained absent from CISA's Known Exploited Vulnerabilities catalog.
Activethehackernews.com -
Jul 23, 2026
A CISA-ADP assessment marked exploitation as none, conflicting with vendor reports of observed attacks.
Activenvd.nist.gov -
Jul 22, 2026
ThreatBook said its platform captured in-the-wild exploitation after adding detection support two days earlier.
Activethehackernews.com -
Jul 21, 2026
Alibaba published its advisory for CVE-2026-16723 following responsible disclosure by Kirill Firsov of FearsOff Cybersecurity.
Emergingthehackernews.com
Sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available The Hacker News Jul 25, 2026
- Unpatched Fastjson Vulnerability Exploited in Attacks SecurityWeek Jul 28, 2026
- FastJson Java library lets attackers run code remotely BleepingComputer Jul 27, 2026
- CVE-2026-16723 detail NVD Jul 23, 2026
- fastjson 1.2.84 Release Notes GitHub Jul 29, 2026
- Security Advisory: Remote Code Execution in fastjson 1.2.68 through 1.2.83 GitHub Jul 29, 2026
Related reports
- FastJson Java bug can let attackers run code remotely Jul 28, 2026
- Alibaba FastJson bug can let attackers run code remotely Jul 27, 2026
- Alibaba FastJson bug can let attackers run commands Jul 23, 2026