Hackers are actively exploiting a remote code execution vulnerability in the FastJson Java library, targeting US firms without requiring user interaction. CISA is monitoring the ongoing exploitation campaign.
1 report · +9 socialother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
🤖 Hackers target US firms in FastJson RCE zero-day attacks. Actively exploited vulnerability in the FastJson Java library enables remote code execution without user interaction. CISA monitoring ongoing. No patch available — only mitigation is blocking JNDI lookups. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/ # CVE # RCE # Exploit #
⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches. https:// threatnoir.com/focus # infosec