FastJson 1.2.83 Remote Code Execution

Author: FearsOff (research team; no individual author bylined) Published: July 21, 2026 (last updated July 26, 2026) Source: https://fearsoff.org/research/fastjson-1-2-83-rce Summary FearsOff disclosed CVE-2026-16723, a remote code execution vulnerability affecting fastjson 1.2.68 through 1.2.83 — including 1.2.83, the final 1.x release long considered the “safe” version because it ships with AutoType disabled by default. The researchers … Read more