CVE-2026-16723
CRITICAL 9.0EPSS 16.0%
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
- CVSS v3.1
- 9.0 CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 9.0 CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 15.99% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2026-07-23
Proof-of-concept exploits (7)
- 1xPwn/CVE-2026-167232★ · 2026-08-16
- HORKimhab/CVE-2026-167231★ · 2026-07-26
- EQSTLab/CVE-2026-167231★ · 2026-07-30
- learner330/fastjson-cve-2026-167234★ · 2026-08-12
- ipisav/fastjson-cve0★ · 2026-08-28
- Superman-L/CVE-2026-167230★ · 2026-08-19
- mekrina/fastjson-1.2.83-rce-research