Alibaba Fastjson SafeMode mitigation for CVE-2026-16723
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code execution in reachable Spring Boot deployments. The advisory says operators that cannot migrate immediately should enable `-Dfastjson.parser.safeMode=true` or switch to `com.alibaba:fastjson:1.2.83_noneautotype`. Fastjson2 remains the long-term fix, and no fixed Fastjson 1.x release was available as of July 25.
Related Happenings
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Fastjson Spring Boot unauthenticated RCE (CVE-2026-16723)
Vulnerability
H score41
First: 25.07.2026 15:52
Last: 25.07.2026 15:52
Sources 1
How related:
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
About this happening:
CVE-2026-16723 is a Fastjson RCE affecting Spring Boot fat-JAR deployments, letting attacker-controlled JSON execute with the Java process's privileges. ThreatBook...
Fastjson Spring Boot unauthenticated RCE (CVE-2026-16723)
VulnerabilityHow related: Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
About this happening: CVE-2026-16723 is a Fastjson RCE affecting Spring Boot fat-JAR deployments, letting attacker-controlled JSON execute with the Java process's privileges. ThreatBook...
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch Release
H score46
First: 17.06.2026 13:09
Last: 17.06.2026 13:09
Sources 1
About this happening:
JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch ReleaseAbout this happening: JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...
Timeline
-
25.07.2026 15:52 3 articles · 13d ago
Alibaba issues SafeMode guidance for affected Fastjson 1.x deployments
Mitigation Patch UpdateAlibaba published guidance for CVE-2026-16723 after responsible disclosure by Kirill Firsov of FearsOff Cybersecurity, telling Fastjson 1.x operators to enable SafeMode with -Dfastjson.parser.safeMode=true or switch to com.alibaba:fastjson:1.2.83_noneautotype while planning a move to Fastjson2.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
- Hackers target US firms in FastJson RCE zero-day attacks — www.bleepingcomputer.com — 28.07.2026 02:49
-
25.07.2026 15:52 1 articles · 13d ago
ThreatBook captures in-the-wild exploitation of CVE-2026-16723
Exploitation ObservedThreatBook said it captured in-the-wild exploitation of CVE-2026-16723 on July 22 after adding detection support two days earlier, indicating active attacker use against Fastjson 1.x deployments.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
-
25.07.2026 15:52 1 articles · 13d ago
CISA marks Fastjson exploitation as none
Untyped PhaseCISA's July 23 ADP assessment marked exploitation as none, even though other reporting had already described observed exploit activity against the Fastjson flaw.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52
-
25.07.2026 15:52 1 articles · 13d ago
Imperva reports targeting across financial, healthcare, computing, and retail organizations
Campaign Scope UpdateImperva reported activity against financial services, healthcare, computing, retail, and other organizations, primarily in the United States with smaller volumes in Singapore and Canada, while Alibaba still had not released a fixed Fastjson 1.x version as of July 25.
Show sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — thehackernews.com — 25.07.2026 15:52