Saltar al contenido principal
Volver a noticias
enterprise security The Hacker News Verificada

Vulnerabilidad RCE en Fastjson 1.x objetivo de ataques sin parche disponible

Fastjson RCE Vulnerabilidad Spring Boot Java

Resumen

La vulnerabilidad CVE-2026-16723 en la biblioteca Fastjson de Alibaba permite la ejecución de código sin autenticación en aplicaciones Spring Boot afectadas. Los atacantes pueden aprovechar esta falla crítica para ejecutar código con los privilegios del proceso Java. La vulnerabilidad tiene una puntuación CVSS de 9.0 y no hay un parche disponible.

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires

CompartirXin

Noticias relacionadas