Apache Log4j — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
July 23, 2026
Last Seen
September 8, 2026

Related Threat Clusters

  • Critical OVERPASS Vulnerability in SAP Kernel Exposed

    On September 8, 2026, SAP released critical security updates addressing 20 vulnerabilities, including CVE-2026-44756, a severe memory corruption flaw in the Extended Passport (EPP) processing. This vulnerability, named…

    8 articles · Updated September 8, 2026
  • Critical Vulnerabilities in Oracle Coherence and Access Manager Disclosed

    Multiple vulnerabilities affecting Oracle Coherence and Oracle Access Manager have been disclosed. CVE-2026-60248 and CVE-2026-60295 are critical vulnerabilities in Oracle Coherence, allowing attackers to potentially…

    10 articles · Updated July 23, 2026
  • Log4j2 Deserialization Bypass Enables Remote Code Execution

    Recent research has revealed a vulnerability in Apache Log4j2 that allows remote code execution (RCE) through unsafe Java deserialization. The issue affects versions 2.11.0 to 2.26.1 of log4j-api and 2.8.0 to 2.26.1 of…

    8 articles · Updated August 27, 2026

Recent Intelligence Reports

  • September 2026 security updates — support.sap.com · September 8, 2026
  • New research raises questions around Log4j 2 LogEvent deserialization — Fieldeffect · August 28, 2026
  • Oracle Issues Record-Breaking July 2026 Security Update with 1,449 Patches BeyondMachines / 4h This release, issued on July 21, 2026, delivers 1,449 new security patches across dozens of product families, patching vulnerabilities in both Oracle's own code and the third-party components bundled within its products. A large concentration of critical flaws affects Oracle Fusion Middleware, which alone received 355 patches, 219 of them remotely exploitable without credentials. — beyondmachines.net · July 23, 2026

CVSS v3.1 Breakdown