CVE-2026-16723: the unpatched Fastjson zero-day hiding in your Java dependencies
Fastjson 1.x has a critical remote code execution flaw under active exploitation, and no 1.x patch is coming. How to find it in your stack —even transitively— and shut the path down.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador