July 28, 2026
- FastJson is under active zero-day exploitation against US firms, this time via fastjson2's default polymorphic parsing — attacker-controlled
@typecan trigger remote class loading or SSRF even with autoType disabled (BleepingComputer, PoC lab); this follows last week's fastjson 1.x RCE coverage (earlier coverage). · Vulnerabilities & Exploits