Threat actors are actively exploiting a remote code execution (RCE) vulnerability in the FastJson Java library, placing organizations across multiple industries at risk. Key takeaways of the FastJson RCEThreat actors are actively exploiting CVE-2026-16723, a FastJson remote code execution vulnerability affecting versions 1.2.68 through 1.2.83. FastJson RCE targets multiple industriesThreatBook first observed active exploitation of CVE-2026-16723 last week, prompting further investigation into the campaign. AdvertisementHow the FastJson RCE vulnerability worksThe vulnerability, CVE-2026-16723, stems from FastJson’s type-resolution logic, which performs attacker-controlled resource lookups before enforcing its AutoType security restrictions. Test incident response plans for Java remote code execution scenarios to validate detection, containment, credential rotation, and recovery procedures before an attack occurs.