
Critical Fastjson 1.x flaw lets attackers run code in Spring Boot apps with no patch available
A critical remote code execution vulnerability in Alibaba's Fastjson 1.x library, tracked as CVE-2026-16723, is being actively exploited against Spring Boot applications, and no official patch exists for the affected 1.x branch as of July 25, 2026.










