Java
Fastjson 1.x RCE (CVE-2026-16723) Under Active Attack — No Patch Coming
A pre-auth RCE in Fastjson 1.2.68–1.2.83 requires no AutoType and no gadget chain, is already under active attack across US, Singapore, and Canadian targets, and Alibaba has confirmed the 1.x line will not get a fix.