Back to news

Active RCE Exploits Hit Fastjson; LG Moves to Purge Proxy Apps from Smart TVs

Two separate security developments this week expose hidden risks in widely deployed software and consumer hardware.

Active RCE Exploits Hit Fastjson; LG Moves to Purge Proxy Apps from Smart TVs

What happened

Attackers are actively exploiting a critical remote code execution vulnerability in Fastjson 1.x, Alibaba's widely used Java JSON parsing library. Tracked as CVE-2026-16723 and rated 9.0 on Alibaba's CVSS scale, the flaw allows an unauthenticated attacker to execute arbitrary code by sending a crafted JSON payload to a vulnerable Spring Boot application, inheriting whatever privileges the underlying Java process holds. Security firms ThreatBook and Imperva have confirmed in-the-wild attack chains, and no official patch is currently available. Separately, LG Electronics USA announced it will suspend webOS smart TV applications found to be silently enrolling consumers' televisions as residential proxy nodes — a practice discovered in more than 42 percent of apps sampled from its store.

Why it matters for your business

Fastjson is embedded across a broad swath of enterprise Java applications, and the absence of a patch means organizations relying on Fastjson 1.x face a wide-open attack surface with no vendor fix to deploy. Engineering and security teams should treat any internet-facing Spring Boot service using the library as compromised until mitigating controls — network segmentation, web application firewall rules blocking suspicious JSON structures, and least-privilege Java process accounts — are in place. The LG story carries a subtler enterprise risk: corporate devices on shared networks, including smart TVs in conference rooms and common areas, could be quietly routing third-party traffic, muddying network forensics and potentially exposing internal traffic patterns. Organizations should audit IoT and smart-display hardware on their networks and apply firmware updates as LG rolls out its app enforcement policy.

What to watch next

All eyes are on Alibaba for a Fastjson patch timeline; the longer the gap, the more sophisticated the exploit kits targeting it will become, following a familiar pattern seen with Log4Shell. On the consumer hardware front, LG has not disclosed a firm deadline for its proxy-app ban, and it remains unclear whether competing smart TV platforms — Samsung Tizen, Google TV, Amazon Fire TV — have conducted equivalent audits of their own app ecosystems. Regulatory scrutiny of residential proxy abuse through consumer IoT devices is also likely to intensify in the EU and US.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp