What is CVE-2026-16723?
A critical remote code execution (RCE) vulnerability in Fastjson 1.x library with no patch available. It allows unauthenticated code execution via malicious JSON requests in affected Spring Boot applications. Security firms warn of active exploitation.
Azərbaycanca: Fastjson 1.x kitabxanasında aşkar edilmiş kritik uzaqdan kod icrası (RCE) zəifliyidir və hələlik rəsmi yamaq yoxdur. Spring Boot tətbiqlərində autentifikasiya olmadan zərərli JSON sorğusu ilə kod icrasına imkan verir. Təhlükəsizlik mütəxəssisləri aktiv istismar halları barədə xəbərdarlıq edir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which library does CVE-2026-16723 affect and is there an official patch currently available?
This vulnerability affects the Fastjson 1.x library. There is currently no official patch available for this critical remote code execution (RCE) issue.
Under what conditions can an application be attacked using the CVE-2026-16723 vulnerability?
Security firms warn of active exploitation. The attack allows unauthenticated code execution by sending a malicious JSON request, particularly in affected Spring Boot applications.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.