July 26, 2026
- Fastjson 1.x RCE (CVE-2026-16723) is now under active attack with no fix available from Alibaba, per The Hacker News. In affected Spring Boot apps, a crafted JSON request executes code unauthenticated at the Java process's privilege (earlier research). · Vulnerabilities & Exploits
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts