IncidentFastjson RCE: When Your Library Maintainer Can't Ship a Patch
Your Spring Boot application uses Fastjson 1.x for JSON parsing. Threat actors are exploiting CVE-2026-16723 in the wild. The CVSS score is 9.0. As of July 25, Alibaba hasn t released a patched versio














