Risky Bulletin Newsletter
July 27, 2026
Risky Bulletin: A JSON RCE bug is about to rock the Java world
Presented by
News Editor
Threat actors are exploiting a vulnerability in Alibaba's Fastjson, one of the Java ecosystem's most popular libraries for working with JSON-formatted data.
Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm FearsOff.
The attacks, first spotted and documented by Imperva and ThreatBook, target CVE-2026-16723, a vulnerability that can enable unauthenticated remote code execution attacks against Java projects that use the Fastjson library as a component.