SECURITY·중요도 9·2026. 07. 25.·The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
── KO ──────────────────
Fastjson의 RCE 취약점에 대한 공격이 발생하고 있습니다.
보안 회사 ThreatBook과 Imperva는 Alibaba의 JSON 라이브러리 Fastjson의 취약점이 공격의 목표가 되고 있다고 전했습니다. 이 취약점은 Spring Boot 애플리케이션에서 악의적인 JSON 요청이 인증 없이 코드를 실행할 수 있게 해줍니다. CVE-2026-16723로 추적되며, Alibaba가 부여한 CVSS 점수는 9.0입니다.
── EN ──────────────────
Attacks are targeting an RCE vulnerability in Fastjson.
Security firms ThreatBook and Imperva report that attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. This vulnerability allows malicious JSON requests to execute code in affected Spring Boot applications without authentication. Tracked as CVE-2026-16723, it has a CVSS score of 9.0 assigned by Alibaba.