ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Web Emergency
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Fastjson 1.x RCE: A Practical Guide for System Administrators

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Fastjson 1.x RCE: A Practical Guide for Syste...
  • All articles
  • Categories
  • Tags
  • Statuses

Fastjson 1.x RCE: A Practical Guide for System Administrators

Understanding the Threat LandscapeIn the ever-evolving world of cybersecurity, staying ahead of threats is a constant challenge. The recent disclosure...

Understanding the Threat Landscape

In the ever-evolving world of cybersecurity, staying ahead of threats is a constant challenge. The recent disclosure of CVE-2026-16723, a critical vulnerability in Fastjson 1.x, has sent ripples through the system administration community. This flaw allows remote code execution (RCE) on servers processing JSON data, with no authentication required and no user interaction needed. For businesses in Spain, from Barcelona to Lleida, this is a wake-up call to reassess their server security posture.

Server rack with a glowing red server and a protective shield above it

The vulnerability affects Fastjson versions 1.2.68 through 1.2.83, including the final release of the 1.x branch. What makes this particularly concerning is that the exploit chain works under common configurations, even with AutoType disabled. The attack leverages deserialization and the use of @type, allowing attackers to control resource lookups before restrictions are applied. This means that even well-configured systems are at risk if they rely on Fastjson 1.x.

Why This Vulnerability Matters for Your Business

For system administrators and hosting companies in Spain, the implications are severe. An RCE vulnerability can lead to complete server compromise, credential theft, and the deployment of additional malicious payloads. The fact that this flaw is being actively exploited, particularly against financial services, healthcare, and retail sectors, underscores the urgency. While reports indicate a concentration of attacks in the United States, signals have also been detected in Singapore and Canada, and the interconnected nature of the internet means no region is immune.

The operational challenge is compounded by the lack of an official patch for Fastjson 1.x. The maintainers have indicated that this branch will not receive a fix, leaving organizations to fend for themselves. This is not a situation where you can simply wait for an update; proactive measures are essential.

Immediate Mitigation Steps

The first line of defense is to enable SafeMode. This can be done in several ways, such as setting the system property -Dfastjson.parser.safeMode=true, or programmatically via ParserConfig.getGlobalInstance().setSafeMode(true). Alternatively, you can modify the fastjson.properties file. SafeMode restricts the types that can be deserialized, effectively blocking the exploit chain.

For a more robust solution, consider switching to a noneautotype build of Fastjson, such as com.alibaba:fastjson:1.2.83_noneautotype. This build removes the automatic type resolution that the attack exploits. However, this is a stopgap measure. The long-term solution is to migrate to fastjson2, which has a more secure design by default, relying on an allowlist approach and not trusting @JSONType annotations.

Practical Steps for System Administrators

As a system administrator, your immediate priority should be to identify all instances of Fastjson 1.x in your infrastructure. Conduct a thorough audit to determine which versions are running, focusing on services exposed to the internet. The exploit is particularly effective against Spring Boot executable fat JARs, so pay special attention to applications started with java -jar.

Once you have a clear picture, take the following actions:

  • Enable SafeMode on all affected instances as a temporary measure.
  • Review and limit endpoints that deserialize JSON from client input. If possible, restrict such endpoints to trusted networks.
  • Strengthen input validation to reject suspicious payloads, especially those containing @type.
  • Implement perimeter controls to detect and block attempts to exploit this vulnerability.
  • Monitor for signs of compromise on systems that meet the critical condition of running as Spring Boot fat JARs. Look for unusual network activity or unexpected processes.

These steps are not just about patching a vulnerability; they are about adopting a proactive security mindset. In the context of GDPR and local regulations, protecting customer data is paramount. A breach could lead to significant fines and reputational damage.

How ALMC.es Can Help

At ALMC.es, we understand the complexities of server security. Our Abuse Shield service is designed to centralize and automate the protection of your servers. It provides automatic blocking of malicious IPs, managed fail2ban across multiple machines, and a shared reputation feed that benefits all your servers. This means that if one server detects a threat, all others are immediately protected.

With Abuse Shield, you can focus on your core business while we handle the heavy lifting of cybersecurity. Our team in Lleida is ready to assist you in securing your infrastructure against threats like CVE-2026-16723 and future vulnerabilities. Don't wait until it's too late; take action today to safeguard your digital assets.

Related

  • Gitea Critical Flaw: Git Hooks Open Door to Server Takeover
  • Cisco FMC zero-day exploited: what sysadmins must do now
  • Coldcard Flaw: How Weak Seed Entropy Led to a $88M Bitcoin Heist
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Server Management & Monitoring
Code Maintenance and Optimization
Cloud Security (AWS, Azure, Google Cloud)
Compliance Consulting (GDPR, ENS, ISO 27001)
Performance Optimization
Relacionados
  • Critical LoadMaster RCE: What Sysadmins Must Do Now
    Cybersecurity · 57 minutes ago
  • CISA Warns: Actively Exploited SharePoint RCE Vulnerability
    Cybersecurity · 57 minutes ago
  • Opera GX Patch: Guarding Against Malicious Browser Mods
    Cybersecurity · 57 minutes ago
  • Azure CLI Password Spraying: Lessons for Server Security
    Cybersecurity · 57 minutes ago
  • SonicWall SMA1000 Zero-Days: Urgent Patch Guidance for SysAdmins
    Cybersecurity · 1 hour ago
  • UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Git Mob
    Version Control
  • Ref
    Official 🌟 Oficial
  • StarRocks
    Official 🌟 Oficial
  • Jira MCP Server
    Productivity
  • Replicate FLUX.1 Kontext [Max]
    Development
  • AgentPay
    Other
  • MCP Prompt Collector
    Development
  • Smithery Reference Servers
    Development
  • Email MCP Server
    Communication
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar