securityonline.info 8/26/2026, 9:48:19 AM · external

New Log4j flaw enables RCE via Java deserialization, no CVE yet

New Log4j flaw enables RCE via Java deserialization, no CVE yet
CyberSIXT Evidence Panel
Primary Source github.com

A newly disclosed Log4j vulnerability allows for remote code execution via unfiltered Java deserialization, impacting countless Java applications. This flaw, detailed on August 24, 2026, has no assigned CVE or patch yet, though a configuration workaround is available. It affects log4j-api versions 2.11.0 to 2.26.1 and log4j-core versions 2.8.0 to 2.26.1 across all JDK versions.

Attackers could exploit this vulnerability by sending crafted messages to a FOIS-based log receiver, avoiding detection due to insufficient filtering. Users are advised to implement workarounds and monitor for updates on the Apache issue tracker.

View Primary Source Via securityonline.info

Article by CyberSIXT