Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Published 13 Sep 2026Updated 13 Sep 20263 sources
CVSS 10.0 PoC CANDIDATE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.