Apache Log4j

2 known vulnerabilities in Apache Log4j, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2021-45046 CVSS 9.0 critical · actively exploited Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Latest vulnerabilities

  • CVE-2026-34479 CVSS 6.9 medium The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing…
  • CVE-2021-45046 CVSS 9.0 critical · actively exploited Apache Log4j2 Deserialization of Untrusted Data Vulnerability