Published 4/17/2017 · updated 5/13/2026 · CWE-502
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Percentile p100 — Higher than 100% of all CVEs — imminent exploitation likely.
Which upstream feeds returned data for this CVE, and when they were last fetched.
Unlock the full report
Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.