CVE-2026-34478Patch(apache / log4j)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache log4j systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes. Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly: * The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output. * The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping. Users of the SyslogAppender are not affected, as its configuration attributes were not modified. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-117CWE-684

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • log4j

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
log4j

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-11: 1Mentions · 2026-06-25: 1Mentions · 2026-08-11: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 104-1106-2508-11
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-111
General1
2026-06-251
Patch1
2026-08-111
Patch1
Full discourse3 posts
  • arcserve Japan合同会社@Arcserve_jp
    Patch

    Arcserve Backup の新規サポート技術情報です🌟 Arcserve Backup 19 | Vulnerability | CVE-2026-34477, CVE-2026-34480, CVE-2025-68161, CVE-2026-34478, and CVE-2026-49844 https://support.arcserve.com/s/article/KB000011092?language=ja

    Post summary

    The post lists five CVEs related to Arcserve Backup 19 and links to a support article, but it does not provide details on exploits, patches, or technical aspects of the vulnerabilities.

    00020296
    7.9K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Urgent: Recent #Cybersecurity flaws impacting data in transit. Apache Log4j TLS bypass (CVE-2026-34478) allows MITM. Cisco SD-WAN zero-day (CVE-2026-20245) grants root, exposing traffic. Patch now! #Vulnerabilities #News

    Post summary

    Two critical vulnerabilities—Apache Log4j TLS bypass (CVE-2026-34478) enabling MITM and Cisco SD-WAN zero-day (CVE-2026-20245) granting root—have been disclosed, and patches are now available.

    0000072
    14 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34478 Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log in… https://www.cve.org/CVERecord?id=CVE-2026-34478

    Post summary

    The entry notes CVE‑2026‑34478 affecting Log4j Core's Rfc5424Layout in specific versions, but provides no further details on the vulnerability, exploitation, or remediation.

    00000209
    57.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelog4j---
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--

Explore more