VDB
CVE-2026-49844
CVE-2026-49844
PUBLISHED
Apache log4j ist ein Framework zum Loggen von Anwendungsmeldungen in Java. Apache Log4cxx ist ein Logging-Framework für C++-Anwendungen, das flexible und konfigurierbare Logging-Funktionen bereitstellt.
EPSS 0.81% · 55.2th percentile
Risk Scores
EPSS Score
0.81%
55.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apache log4j <2.25.5 | |
| IBM | IBM License Metric Tool | |
| HCL | HCL Domino Rest API | |
| Apache | Apache log4j <2.26.1 |
Timeline
- Jul 10, 2026 CVE Published
- Jul 11, 2026 EPSS Score
- Jul 11, 2026 Coalition ESS Score
- Jul 13, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2292.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2292 advisory
- https://logging.apache.org/security.html#CVE-2026-49844 advisory
- https://logging.apache.org/security.html#CVE-2026-40023 advisory
- https://www.ibm.com/support/pages/node/7280602 advisory
- https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132666 advisory