Fastjson : une faille critique sans patch exploitée activement

15 sources
  • Une vulnérabilité RCE critique (CVE-2026-16723, CVSS 9,0) dans Fastjson 1.x ne nécessite aucune authentification ni interaction de l'utilisateur pour être exploitée dans les déploiements Spring Boot.
  • Imperva et ThreatBook ont confirmé une exploitation active ciblant les services financiers, la santé et la grande distribution aux États-Unis, alors qu'une preuve de concept publique est désormais disponible.
  • Alibaba n'a pas corrigé la branche 1.x archivée : les entreprises doivent activer le mode SafeMode ou migrer vers Fastjson 2.x comme seule solution durable.
Sources (15)
  1. 1 Fastjson 1.x RCE Vulnerability Targeted in Attacks With No ... thehackernews.com
  2. 2 Critical FastJson 1.x Zero-Day RCE www.imperva.com
  3. 3 FastJson RCE CVE-2026-16723 Exploited, PoC Public securityonline.info
  4. 4 Fastjson RCE (≤1.2.83): Active Exploitation Detected threatbook.io
  5. 5 CRITICAL Alibaba Fastjson 1.2.68 vulnerability (CVE-2026 ... www.instagram.com
  6. 6 📰 Fastjson 1.x RCE Vulnerability Targeted in Attacks With ... www.instagram.com
  7. 7 Remote Code Execution in Fastjson 1.2.68 to 1.2.83 basefortify.eu
  8. 8 CVE-2026-16723 www.tenable.com
  9. 9 Deserialization of Untrusted Data in com.alibaba:fastjson devhub.checkmarx.com
  10. 10 Angelo Caproitti's Post www.linkedin.com
  11. 11 A huge unpatched Alibaba Fastjson flaw is getting abused ... www.reddit.com
  12. 12 Alibaba's Fastjson 1.x Hit by Active RCE Exploits, No Patch aiweekly.co
  13. 13 MagicZer0/fastjson-rce-exploit github.com
  14. 14 CVE-2026-16723 Detail - NVD nvd.nist.gov
  15. 15 Fastjson 1.x RCE Vulnerability Targeted in Attacks With No ... www.threads.com