Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Published 31 Aug 2026Updated 31 Aug 2026454 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

Source timeline

Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗