Alibaba Fastjson 1.x · Authenticated RCE via Jupyter Notebook · SiYuan Note-Taking Application
Date: 2026-07-26 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Today’s most significant new items are an actively exploited unpatched RCE in Alibaba’s Fastjson 1.x library (CVE-2026-16723, CVSS 9.0), a public PoC for a GitLab authenticated RCE flaw (CVE not yet confirmed in data) affecting unpatched self-managed instances, and a novel in-browser malware assembly campaign (SourTrade) targeting retail traders. No new CISA KEV entries or BSI/CERT-EU advisories were published in the last 24 hours.
Critical Vulnerabilities
CVE-2026-16723 — Alibaba Fastjson 1.x (Java JSON Library)
- Severity: CVSS 9.0 (Alibaba-assigned)
- EPSS: Not yet scored
- Technical detail: A critical deserialization/RCE flaw in Fastjson 1.x, Alibaba’s widely deployed JSON library for Java. In affected Spring Boot applications, a crafted malicious JSON request triggers unauthenticated remote code execution with the privileges of the Java process. No patch is currently available for the 1.x branch. Fastjson 1.x remains extremely prevalent in enterprise Java environments, particularly in applications of Chinese origin or those that have not migrated to Fastjson 2.x or alternative libraries.
- Exploitation status: Actively exploited in the wild, confirmed by ThreatBook and Imperva. No patch available.
- Remediation: Migrate to Fastjson 2.x or an alternative JSON library (e.g., Jackson, Gson) immediately. As a compensating control, apply WAF rules to block malicious JSON payloads targeting Fastjson gadget chains, restrict outbound network access from Java application servers, and monitor for anomalous process spawning from JVM processes. Treat any internet-exposed Fastjson 1.x application as potentially compromised pending migration.
GitLab Self-Managed — Authenticated RCE via Jupyter Notebook (PoC Published)
- Severity: Not yet assigned; RCE impact
- EPSS: Not yet scored
- Technical detail: Researchers at depthfirst published a working exploit on 2026-07-24 for a GitLab flaw patched six weeks prior (2026-06-10). Any authenticated user with push access to a project can commit a crafted Jupyter notebook; opening the commit diff triggers a heap memory leak that enables command execution as the
gitsystem user on self-managed GitLab 18.11.3 instances that have not applied the June 10 update. The low privilege bar (any authenticated user) and public PoC significantly lower the exploitation threshold. - Exploitation status: Working public PoC released 2026-07-24; no confirmed in-the-wild exploitation reported yet, but weaponization window is now open.
- Remediation: Apply the GitLab patch released 2026-06-10 immediately. Audit self-managed instances for version compliance. Review GitLab access logs for anomalous Jupyter notebook commits and diff views. Restrict project push access to trusted users where possible.
CVE-2026-66012 — SiYuan Note-Taking Application
- Severity: CVSS 10.0
- EPSS: 0 (newly published)
- Technical detail: A missing authorization vulnerability in SiYuan before v3.7.2 exposes the
POST /mcpkernel endpoint with only a general authentication check (model.CheckAuth), with no admin-role or read-only enforcement. This allows authenticated but low-privileged users to invoke privileged kernel operations. SiYuan is a self-hosted personal knowledge management tool; enterprise relevance is limited but deployments in developer or research environments may be exposed. - Exploitation status: No confirmed exploitation.
- Remediation: Upgrade SiYuan to v3.7.2 or later. Restrict network access to SiYuan instances to trusted hosts only.
CVE-2026-66374 — Knot Resolver (DNS-over-QUIC)
- Severity: CVSS 8.1
- EPSS: 0.39
- Technical detail: A heap-based buffer overflow in Knot Resolver’s DoQ (DNS-over-QUIC) receive path allows remote code execution by sending a crafted QUIC packet to the resolver. Knot Resolver is deployed in European ISP and enterprise DNS infrastructure, including by CZ.NIC. Exploitation requires network access to the DoQ listener (UDP/853 by default) but no authentication. EPSS of 0.39 indicates meaningful near-term exploitation probability.
- Exploitation status: No confirmed exploitation; PoC not publicly known.
- Remediation: Upgrade Knot Resolver to 6.4.1 or later. If DoQ is not required, disable the DNS-over-QUIC listener as a compensating control. Restrict resolver access to authorized clients via firewall rules.
CVE-2026-15962 — Fluent Forms Pro Add On Pack (WordPress)
- Severity: CVSS 8.8
- EPSS: 0 (newly published)
- Technical detail: A PHP Object Injection vulnerability in Fluent Forms Pro Add On Pack for WordPress (all versions ≤ 6.2.6) via deserialization of untrusted input. Exploitation requires a subscriber-level or higher authenticated user, but in typical WordPress deployments with open registration this bar may be low. Successful exploitation can lead to arbitrary code execution depending on available POP chains in the target environment.
- Exploitation status: No confirmed exploitation.
- Remediation: Update Fluent Forms Pro Add On Pack to version 6.2.7 or later. Disable open user registration on WordPress sites where not required.
ONGOING:
Certighost(ADCS domain controller impersonation): working public exploit active; audit certificate templates and monitor DCSync events immediately.Redis(multiple CVEs, versions 6.2–8.8): public PoC available; upgrade to 6.2.23 / 7.2.15 / 7.4.10; apply Redis 8.x patches when released.CVE-2026-59865et al. (Microsoft Kiota): high EPSS; update to ≥ 1.32.5.CVE-2026-58630 / CVE-2026-56163 / CVE-2026-57106(Azure/AKS/Purview CVSS 10.0 cluster): monitor Azure audit logs; no patch action available beyond configuration hardening.CVE-2026-10610(ESET macOS): local privilege escalation; update to latest release.CVE-2026-16232(Check Point SmartConsole): KEV deadline passed — treat unpatched as compromised.CVE-2026-50522(SharePoint): KEV deadline passed — conduct compromise assessment.CVE-2026-0257(PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing; patch immediately.CVE-2026-6875(ServiceNow AI Platform): exploitation continues; patch and restrict access.CVE-2026-6516(ManageEngine ADAudit Plus): unauthenticated RCE; upgrade to build 8606.
European Advisories
No new BSI WID or CERT-EU advisories were published in the last 24 hours.
CVE-2026-66374 (Knot Resolver) is of direct relevance to European DNS infrastructure operators, including ISPs and enterprises using CZ.NIC’s resolver software; see Critical Vulnerabilities for full detail.
Previously reported BSI advisories for JetBrains IDEs, Google Chrome, cPanel/WHM, CyberPanel, and the Microsoft Azure CVSS 10.0 cluster remain actionable — apply vendor patches per prior guidance.
Active Threats and Campaigns
NEW — SourTrade Malvertising (In-Browser Malware Assembly): A malvertising campaign active since late 2024, detailed by Confiant on 2026-07-23, uses fake TradingView, Solana, and Luno pages to deliver malware to retail traders. Malicious JavaScript instructs the victim’s browser to assemble a Windows executable in memory using the legitimate Bun runtime, avoiding static file detection. No single complete malicious binary is served from a fixed URL, complicating traditional IOC-based blocking. Block known malicious domains at DNS/proxy; ensure endpoint detection covers in-memory PE assembly and Bun runtime abuse.
NEW — Steam ClickFix Cryptominer Campaign: Threat actors are posting fake “fix” instructions in Steam discussion forums, directing users to execute commands that install XMRig cryptominers. The ClickFix social engineering technique exploits users’ trust in community forums. Alert gaming-adjacent staff and enforce application allowlisting to block unauthorized miner execution.
NEW — ShinyHunters Breach Data Fueling Sextortion Campaign: Threat actors are leveraging email addresses from ShinyHunters data breach leaks to send targeted sextortion emails demanding $2,000 in Bitcoin. Organizations should alert staff to disregard these emails and report them; no credential or system compromise is implied by receipt.
ONGOING — Clop Targeting PTC Windchill/FlexPLM: No new technical developments; restrict internet exposure and investigate for data exfiltration indicators per yesterday’s guidance.
ONGOING — BlueNoroff Zoom/Teams Phishing Kit: No new developments; enforce VPN and verify videoconferencing invitations.
ONGOING — UAC-0099 Fake Notepad++ Plugin (MATCHBOIL.V2): No new developments; block unsigned Notepad++ plugins.
Security News and Context
- Fastjson 1.x active exploitation: ThreatBook and Imperva confirmed in-the-wild attacks against the unpatched Fastjson 1.x RCE; no fix available — migration to Fastjson 2.x is the only remediation. (The Hacker News)
- GitLab RCE PoC published: depthfirst released working exploit code on 2026-07-24 for a patched GitLab flaw; self-managed instances on 18.11.3 without the June 10 update are at immediate risk. (The Hacker News)
- DevMan RaaS portal: PRODAFT (Swiss) is tracking a new RaaS operation (“Funky Mantis”) offering affiliates a centralized portal for payload builds, victim management, and payouts. (The Hacker News)
Recommended Actions
- Fastjson 1.x (CVE-2026-16723): Migrate to Fastjson 2.x or an alternative library immediately; apply WAF rules and restrict JVM outbound access as compensating controls; treat exposed instances as potentially compromised.
- GitLab self-managed: Apply the 2026-06-10 patch immediately; audit logs for anomalous Jupyter notebook activity; restrict push access to trusted users.
- Knot Resolver (CVE-2026-66374): Upgrade to 6.4.1; disable DoQ listener if not required; restrict resolver access by firewall.
- Fluent Forms Pro (CVE-2026-15962): Update to ≥ 6.2.7; disable open WordPress registration where not needed.
- SiYuan (CVE-2026-66012): Upgrade to v3.7.2; restrict network access to trusted hosts.
- SourTrade malvertising: Block malicious domains at DNS/proxy; ensure endpoint detection covers in-memory PE assembly and Bun runtime abuse targeting retail trader platforms.
- Steam ClickFix: Alert staff; enforce application allowlisting to block unauthorized cryptominer execution.
- ShinyHunters sextortion: Brief staff to disregard and report $2,000 Bitcoin sextortion emails; no system action required.
- WPForms Pro (CVE-2026-10818, EPSS 0.42): Update to ≥ 1.10.1.2; restrict file upload functionality to authorized roles.
- Continue remediation of previously reported items: Certighost (ADCS), Redis RCE, Microsoft Kiota, Azure CVSS 10.0 cluster, ESET macOS (CVE-2026-10610), CVE-2026-16232 (Check Point — treat as compromised), CVE-2026-50522 (SharePoint — compromise assessment), CVE-2026-0257 (PAN-OS), CVE-2026-6875 (ServiceNow), CVE-2026-6516 (ManageEngine).