Log4j - Vulnerability

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
November 20, 2025
Last Seen
June 3, 2026

Log4j is a vulnerability tracked across 14 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity June 3, 2026.

Related Threat Clusters

  • New CVSS 10.0 Vulnerability CVE-2026-29000 Discovered

    A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…

    2 articles · Updated March 6, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    689 articles · Updated April 29, 2026
  • Critical React Flaw CVE-2025-55182 Exposes Major Security Risks

    A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…

    47 articles · Updated December 3, 2025
  • APT41 Cyber-Espionage Tactics Explored in Ransomware Emulations

    The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…

    14 articles · Updated January 6, 2026
  • Burp Suite Enhances Scanner for React2Shell Vulnerabilities

    Burp Suite has upgraded its scanning capabilities to detect critical React2Shell vulnerabilities in JavaScript applications. Both editions of Burp Suite now include the latest detection logic, allowing users to validate…

    4 articles · Updated December 9, 2025
  • CISA Warns of Active Exploitation of Oracle Identity Manager Vulnerability CVE-2025-61757

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw…

    31 articles · Updated November 26, 2025
  • Oracle Identity Manager RCE Vulnerability Exploited in Active Attacks

    A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively…

    19 articles · Updated November 21, 2025
  • Critical Oracle Identity Manager RCE Vulnerability Exploited

    A critical remote code execution vulnerability, tracked as CVE-2025-61757, has been identified in Oracle Identity Manager. This flaw allows unauthenticated attackers to execute code remotely and has been actively…

    4 articles · Updated November 21, 2025
  • Software Supply Chain Threats Surge to OWASP Top 10

    Software supply chain security has gained prominence, now ranking third on the OWASP Top 10 list for 2025. This shift reflects a rise in attacks targeting the foundational components of software, which exploit trust in…

    2 articles · Updated January 9, 2026
  • Apache Log4j Vulnerability Exposes Sensitive Log Data to Attackers

    Apache Logging Services has disclosed a critical vulnerability in Log4j Core that allows attackers to intercept sensitive log data. This flaw affects versions 2.0-beta9 through 2.25.2, specifically in the Socket…

    4 articles · Updated December 19, 2025

Recent Intelligence Reports

  • Cybersecurity PR Agencies - Best Picks 2026 — Analyticsinsight · June 3, 2026
  • Cybersecurity PR Agencies - Best Picks 2026 — Analyticsinsight · June 3, 2026
  • Hacker hijacks Axios open-source project, used by millions, to push malware — Techcrunch · March 31, 2026
  • Cobalt Introduces New AI Capabilities for Continuous Pentesting — Sg.Finance.Yahoo · March 19, 2026
  • Why CVSS 10 Vulnerabilities Are So Dangerous (Real Examples) — Codeant.Ai · March 6, 2026
  • Modern Vulnerability Management in the Age of AI — Sonatype · February 25, 2026
  • SUSE log4j Medium Risk Security Update for CVE-2025 — Linuxsecurity · January 23, 2026
  • Software supply chain threats are finally on the OWASP Top 10 — Scworld · January 9, 2026

CVSS v3.1 Breakdown