enterprise security The Hacker News Verificada
Vulnerabilidad RCE en Fastjson 1.x objetivo de ataques sin parche disponible
Fastjson RCE Vulnerabilidad Spring Boot Java
Resumen
La vulnerabilidad CVE-2026-16723 en la biblioteca Fastjson de Alibaba permite la ejecución de código sin autenticación en aplicaciones Spring Boot afectadas. Los atacantes pueden aprovechar esta falla crítica para ejecutar código con los privilegios del proceso Java. La vulnerabilidad tiene una puntuación CVSS de 9.0 y no hay un parche disponible.
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires