Apache Log4j Core
4 known vulnerabilities in Apache Log4j Core, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-34480 CVSS 6.9 medium Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3…
- CVE-2026-34478 CVSS 6.9 medium Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through…
- CVE-2026-34477 CVSS 6.3 medium The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only…
- CVE-2025-68161 CVSS 6.3 medium The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer…