SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16723

CRITICAL · CVSS 9 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

Fastjson versions 1.2.68 to 1.2.83 are susceptible to a critical remote code execution vulnerability that can be exploited without requiring AutoType enablement or any classpath gadgets, making it particularly dangerous in its default configuration. Organizations using these versions should prioritize immediate patching or mitigation strategies to prevent potential exploitation, as attackers can execute arbitrary code remotely. This vulnerability poses a significant risk to any application relying on fastjson for JSON processing.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16723
Severity
CRITICAL
CVSS
9
EPSS
0.41%

Original NVD Description

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.