Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
2026-07-25T19:24:07Z•7b4b6ace0b8b9aefa58c8e8149c7c9186dd72014003329a625150b64bfb8a3ac
active-exploitationactive-poccloud-infrastructureidentity-theftphishingprivilege-escalationransomwareremote-code-executionsupply-chainzero-day
What happened
Multiple high-impact vulnerabilities and active exploitation campaigns reported across web, cloud, and enterprise software. Notable items: Fastjson 1.x RCE (CVE-2026-16723) being actively targeted with no patch available; a public GitLab RCE PoC affecting unpatched self-managed 18.11.3 instances; Cl0p affiliates exploiting unauthenticated RCEs in PTC Windchill/FlexPLM for data extortion; Certighost exploit allowing low-privileged AD users to obtain Domain Controller certificates and perform DCSync; Redis-authenticated RCE chains and related emergency releases; Bing Images crafted-SVG flaws (CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7b4b6ace0b8b9aefa58c8e8149c7c9186dd72014003329a625150b64bfb8a3ac
- Enrichment time
- 2026-07-25T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.