CRITICAL ⚡ MUST-KNOW
Unpatched Fastjson Vulnerability Exploited in Attacks
An unpatched vulnerability in Fastjson, a widely used Java JSON library, is being actively exploited in attacks. The flaw allows unauthenticated remote code execution under the library’s stock default configuration. No patch is currently available, so organizations using Fastjson should review configurations and apply compensating controls, such as disabling autotype features or restricting network exposure, until a fix ships.