Critical Fastjson 1.x RCE Exploitation in Spring Boot
🛡️ Security firms ThreatBook and Imperva report active exploitation attempts targeting a critical remote code execution flaw in Fastjson 1.x, affecting Spring Boot executable fat-JAR deployments. Tracked as CVE-2026-16723 with an Alibaba CVSS of 9.0, the chain impacts Fastjson 1.2.68–1.2.83 when SafeMode is disabled and can execute code without AutoType or classpath gadgets. Alibaba has not yet released a 1.x patch; recommended mitigations include enabling SafeMode or using the 1.2.83_noneautotype build and migrating to Fastjson2 long-term.
