Critical RCE Vulnerability in fastjson Disclosed (CVE-2026-16723)

Critical RCE Vulnerability in fastjson Disclosed (CVE-2026-16723)

First seen 23 Jul 2026, 18:34 UTC Feedlycve.akaoma.comcve.reportvulners.comvulnerability.circl.lu 90% similarity 74.0

Article Content

Browse articles
ThreatCluster

A remote code execution (RCE) vulnerability, CVE-2026-16723, has been identified in fastjson versions 1.2.68 to 1.2.83. This vulnerability can be exploited without requiring AutoType enablement or classpath gadgets, making it particularly dangerous. An unauthenticated attacker can execute arbitrary code on systems using the affected library over the network. The CVSS score for this vulnerability is 9.0, indicating a severe risk. Currently, there is no evidence of public proof-of-concept or confirmed exploitation. Cybersecurity professionals are urged to update fastjson to versions beyond 1.2.83 and restrict network access to vulnerable applications. The vulnerability was published on July 23, 2026, and is considered an immediate threat requiring urgent mitigation.

Key Points: • CVE-2026-16723 is a critical RCE vulnerability in fastjson versions 1.2.68 to 1.2.83. • Exploitation does not require AutoType enablement or classpath gadgets. • Immediate action is needed: update fastjson and restrict network access.

ThreatCluster AI

Timeline

2026-07-23
CVE-2026-16723 published
A remote code execution vulnerability in fastjson was disclosed, affecting versions 1.2.68 to 1.2.83.
Feedly
2026-07-23
Severity rating assigned
CVE-2026-16723 received a CVSS score of 9.0, indicating severe risk.
cve.akaoma.com
2026-07-23
Urgent mitigation recommended
Cybersecurity professionals are advised to update fastjson and monitor for exploitation attempts.
cve.report

Community

Browse all →