Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Fastjson Software Could Let Hackers Take Control

A serious security weakness has been found in certain versions of Fastjson, a software tool used to process data. This flaw could allow hackers to run harmful code on affected systems without needing special settings enabled. It is important because many small businesses may use software that includes Fastjson, putting their systems at risk.

26 July 2026

Reference: CVE-2026-16723

1. What is being reported?

Researchers have discovered a critical vulnerability in Fastjson versions 1.2.68 through 1.2.83. This flaw allows attackers to execute malicious commands remotely, meaning they can potentially take control of a system using these versions without any extra configuration needed.

2. What this means in plain English

If your business uses software that relies on these versions of Fastjson, hackers could exploit this weakness to access your systems, steal data, or cause damage. This risk is serious because it does not require any special settings to be turned on, making it easier for attackers to succeed.

3. Could this affect a small business?

Small businesses that use software or services incorporating Fastjson versions 1.2.68 to 1.2.83 could be affected. If you do not know whether your software uses Fastjson, or which version, you should check with your IT provider. Organisations not using this software are unlikely to be affected.

4. What to do now

  • Ask your IT provider or software supplier if any of your systems use Fastjson versions 1.2.68 to 1.2.83.
  • If affected, request immediate updates or patches to fix the vulnerability.
  • Ensure your software and systems are kept up to date with the latest security fixes.
  • Monitor your systems for any unusual activity and report concerns promptly.

5. Ask your IT provider

Can you confirm whether any of our software uses Fastjson versions 1.2.68 through 1.2.83, and if so, what steps are being taken to protect us from the known remote code execution vulnerability?

6. Bottom line

Check with your IT support now to ensure your systems are not vulnerable to this critical Fastjson security flaw.

Information based on NVD, CISA KEV, and reputable security news reporting.

Back to Vulnerability Briefs