Risky Bulletin: A JSON RCE bug is about to rock the Java world




This newsletter is brought to you by application allow-listing software maker Airlock Digital. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
Threat actors are exploiting a vulnerability in Alibaba's Fastjson, one of the Java ecosystem's most popular libraries for working with JSON-formatted data.
Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm FearsOff.
The attacks, first spotted and documented by Imperva and ThreatBook, target CVE-2026-16723, a vulnerabilit…