Fastjson 1.x Will Never Be Patched — Your Java Backend Is One JSON Request Away from Total Compromise
CVE-2026-16723 (CVSS 9.0) enables unauthenticated RCE on Fastjson 1.x with no patch forthcoming — ever. Enable SafeMode immediately and plan your Fastjson 2.x migration. Here is the three-step response plan.