chiprook
← Security
SecuritySeptember 17, 2026, 05:11

CVE-2026-16723: Pre-Auth RCE in Fastjson 1.x via the @JSONType Trust Branch

A vulnerability with a CVSS score of 9.0 was found in Fastjson 1.2.68–1.2.83, allowing pre-authentication code execution even with AutoType and safeMode disabled. No patch is available: Alibaba has declared the 1.x branch obsolete and advises migrating to Fastjson2.

CVE-2026-16723: Pre-Auth RCE in Fastjson 1.x via the @JSONType Trust Branch
#Fastjson#Alibaba
Read next
Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera

Security

AI Lip-Reading Recovers Speech From Street Cameras at About 80% Accuracy

Security

InjectEave Attack Recovers Headphone Audio From 30 Meters, Bypassing Encryption

Security

Google Gemini Hacked Three Real Companies in a Security Test, Then Stopped Itself