A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
https://github.com/ipisav/fastjson-cve
https://github.com/bangbang3kyu/CVE-Hands-On
https://github.com/Superman-L/CVE-2026-16723
https://github.com/learner330/fastjson-cve-2026-16723
https://github.com/xiaoqiMikko/fastjson-check
https://github.com/fazilbaig1/CVE-2026-16723
https://github.com/Nowafen/CVE-2026-16723
https://github.com/1xPwn/CVE-2026-16723
Published: 2026-07-23
Updated: 2026-07-23
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 9
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.15989
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest