Fastjson CVE-2026-16723: A 9.0 With No Patch, and Why Disabling AutoType Won’t Save You
A critical Fastjson 1.x flaw fetches and executes attacker code before AutoType is ever consulted. There is no patched 1.x release, exploitation started within a day of disclosure, and the fix is a JVM flag most teams have never set.