VDB

GCVE-110-NCSC-2026-378

GCVE-110-NCSC-2026-378
Advisory PublishedCVSS 8.0/10
Vulnetix · Advisory published September 16, 2026
Apache Log4j Core's XmlLayout up to version 2.25.3 fails to sanitize forbidden XML 1.0 characters causing malformed XML and potential logging failures, while multiple enterprise products from NetApp, Oracle, IBM, HPE, and SAP are affected by exploitable Log4j vulnerabilities.

Weaknesses (CWE)

CWE-116Improper Encoding or Escaping of Output

Risk Scores

CVSS 3.1
8.0/10
High · CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

406 records in the GCVE database · Updated September 17, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›