Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fastjson Vulnerability Exploited in Active Attacks

Fastjson Vulnerability Exploited in Active Attacks

Posted on July 25, 2026 By CWS

Security experts have identified an ongoing exploitation of a significant vulnerability in Fastjson, a JSON library developed by Alibaba for Java. This flaw, impacting certain Spring Boot applications, allows unauthorized code execution with the same permissions as the Java process. The vulnerability is designated as CVE-2026-16723 and has been given a high severity score of 9.0 according to the Common Vulnerability Scoring System (CVSS).

Details of the Vulnerability

The affected versions of Fastjson are from 1.2.68 to 1.2.83, particularly within Spring Boot’s executable fat-JARs. The vulnerability can be exploited through a network-accessible path that processes attacker-controlled JSON data, especially if the SafeMode feature is not enabled, which is its default setting. Notably, the exploitation does not require AutoType to be active or a specific classpath gadget.

As of July 25, no patched version has been released by Alibaba. Organizations using Fastjson are advised to enable SafeMode by configuring with -Dfastjson.parser.safeMode=true or using a restricted build like com.alibaba:fastjson:1.2.83_noneautotype. Transitioning to Fastjson2 is recommended as a permanent solution.

Analysis of Exploit Techniques

The vulnerability’s roots lie in Fastjson’s type-resolution mechanism, where an attacker can manipulate the @type value leading to a class-resource lookup. This method works effectively in systems using Spring Boot fat-JARs, facilitating the execution of attacker-supplied bytecode. Additionally, @JSONType annotations can be misused as trust indicators, allowing malicious classes to bypass type checks.

Security firm ThreatBook reported observing real-world exploitation shortly after deploying detection methods. It noted successful execution of code within a Spring Boot fat-JAR environment running JDK 8, although other tests resulted in limited outcomes such as remote JAR retrievals.

Impact on Various Sectors

Imperva highlighted that sectors like financial services, healthcare, and retail in the United States are primarily targeted, with some activity detected in Singapore and Canada. The majority of attacks involved browser impersonation techniques, with Ruby and Go tools accounting for a substantial portion of the attack methods.

Despite the observed exploitation, no concrete evidence of successful breaches has been published by the vendors. The Cybersecurity and Infrastructure Security Agency (CISA) also noted the absence of this vulnerability in its Known Exploited Vulnerabilities catalog, indicating no official confirmation of successful attacks.

Recommendations for Organizations

Organizations are urged to assess their systems for Fastjson dependencies, particularly looking for suspicious @type values and other anomalies. Transitioning to Fastjson2 is strongly advised, as it is not susceptible to the same exploitation techniques. Ongoing vigilance and system audits are essential to mitigate potential risks associated with this vulnerability.

The Hacker News reached out to Alibaba and Imperva for further clarification on the vulnerability and its exploitation, with updates to follow pending responses. In the meantime, Fastjson 1.2.83 remains the latest available version, although it falls within the affected range for the identified flaw.

The Hacker News Tags:Alibaba, Attack, CVE-2026-16723, Cybersecurity, Fastjson, financial services, Healthcare, Java, JDK, SafeMode, Spring Boot, Vulnerability

Post navigation

Previous Post: Rockwell Fixes Critical Flaws in Arena Software
Next Post: Phishing Threats Evolve to Real-Time Insurance Account Hijacking

Related Posts

Critical SGLang Vulnerability Allows Remote Code Execution Critical SGLang Vulnerability Allows Remote Code Execution The Hacker News
VECT 2.0 Ransomware Permanently Destroys Large Files VECT 2.0 Ransomware Permanently Destroys Large Files The Hacker News
Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams The Hacker News
The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations  The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations  The Hacker News
U.S. Halts Xinbi Scam Network, Freezes .8M in Crypto U.S. Halts Xinbi Scam Network, Freezes $52.8M in Crypto The Hacker News
ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Exploit AD Replication for Credential Theft
  • AI Researcher Resigns, Warns of Development Dangers
  • Abuse of Google Play Early Access for Deceptive Apps
  • Critical LiteLLM Vulnerability Risks Cloud Security
  • Fraudulent Apps Exploit Google Play’s Early Access Program

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Exploit AD Replication for Credential Theft
  • AI Researcher Resigns, Warns of Development Dangers
  • Abuse of Google Play Early Access for Deceptive Apps
  • Critical LiteLLM Vulnerability Risks Cloud Security
  • Fraudulent Apps Exploit Google Play’s Early Access Program

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark