CVE-2025-68161Patch(apache / log4j)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache log4j systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-297CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • log4j

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-11); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
log4j

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-21: 1Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-08-11: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-04-11: 103-1103-2104-1004-1108-11
Signal classification2 categories
Patch
466.7%
General
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-112
Patch2
2026-03-211
Patch1
2026-04-101
General1
2026-04-111
Patch1
2026-08-111
General1
Full discourse6 posts
  • arcserve Japan合同会社@Arcserve_jp
    General

    Arcserve Backup の新規サポート技術情報です🌟 Arcserve Backup 19 | Vulnerability | CVE-2026-34477, CVE-2026-34480, CVE-2025-68161, CVE-2026-34478, and CVE-2026-49844 https://support.arcserve.com/s/article/KB000011092?language=ja

    Post summary

    The tweet merely lists several CVE identifiers for Arcserve Backup and provides a link to a support article, but offers no details about exploitation, patches, or technical specifics.

    00020296
    7.9K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34477 The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log… https://www.cve.org/CVERecord?id=CVE-2026-34477

    Post summary

    The text notes an incomplete fix for a related CVE and references the CVE‑2026‑34477 record, but offers no exploit or technical details.

    00010211
    57.1K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to 2/3

    Post summary

    The update to Dataproc Metastore Proxy includes fixes for five CVEs accompanied by a version upgrade.

    1000032
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and CVE-2025-33042. 2/4

    Post summary

    The text announces that multiple CVEs have been fixed, highlighting a patch release without providing detailed vulnerability or exploitation information.

    1000098
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.1.110-ubuntu20-arm 2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and 2/4

    Post summary

    The statement lists package versions that have fixed four CVEs, signaling that these vulnerabilities have been addressed.

    1000088
    1.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34477 The fix for CVE-2025-68161 http://logging.apache.org/security.html#CVE-2025-68... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34477 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet shares links to vulnerability detail pages for CVE‑2026‑34477 without noting any PoC, exploit, remediation, or technical specifics.

    00000147
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelog4j---
Appapachelog4j2.0--
Appapachelog4j2.0--
Appapachelog4j2.0--
Appapachelog4j2.0--
Appapachelog4j2.0--

Explore more