Critical Fastjson vulnerability allows remote code execution as hackers exploit 0-Day to attack US organizations
FearsOff CybersecurityFastJson

Critical Fastjson vulnerability allows remote code execution as hackers exploit 0-Day to attack US organizations

A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against U.S. organizations, allowing remote code execution without valid credentials. The flaw affects versions 1.2.68 to 1.2.83, with a CVSS score of 9.0, prompting urgent migration to FastJson 2.x for affected users.

CyberSecurityNews CyberSecurityNews29 July 2026 · 00:31 UTC
CuriousCats Full Story

A critical vulnerability in FastJson, known as CVE-2026-16723, is currently being exploited against U.S. organizations, posing a significant risk to Java applications.

Disclosed on July 21, 2026, by FastJson maintainers after research from FearsOff Cybersecurity, this flaw has a CVSS severity score of 9.0 and affects FastJson versions 1.2.68 to 1.2.83, the last release line of FastJson 1.x.3

The vulnerability is particularly severe as attackers do not need valid credentials, user interaction, AutoType enabled, or any in the target application’s classpath to exploit it.

Exploitation attempts have been observed across various sectors, including financial services, healthcare, retail, computing, and business services. While most attacks are targeting U.S. organizations, smaller campaigns have also been noted in Singapore and Canada, with broader exploitation anticipated as public proof-of-concept details become widely available.

Organizations are urged to immediately enable FastJson SafeMode using the command -DFastJson.parser.safeMode=true or by setting ParserConfig.getGlobalInstance().setSafeMode(true). Since FastJson 1.x is no longer actively maintained and no patch is available, affected organizations should prioritize migrating to FastJson 2.x after conducting compatibility testing.2

Key Insight
“The issue was disclosed on July 21, 2026, by FastJson maintainers following research from FearsOff Cybersecurity. Organizations are urged to enable FastJson SafeMode immediately or migrate to FastJson 2.x, as no patch is available for the outdated 1.x version.”
CuriousCats studied:
1
CyberSecurityNewsCyberSecurityNews
“A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java applications that at immediate risk.”
CyberSecurityNews →
Ask CuriousCats
What is the Fastjson vulnerability?
Why is it critical for cybersecurity?
How should organizations respond to this vulnerability?
Are there any patches for Fastjson 1.x?
How does Fastjson 2.x improve security standards?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats