Patch tracker / CVE reference / CVE-2026-34480
CVE-2026-34480
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing m...
Risk summary
Vulnerability, CVSS 7.5 (High).
Senserva AI Opinion and rich prompt for CVE-2026-34480
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
How to fix CVE-2026-34480
Update Apache log4j to version 2.25.4 or later. (Fixed-version data from NVD.) Where a workaround exists, apply it only until the update is deployed, not as a substitute.
Common questions about CVE-2026-34480
Is CVE-2026-34480 actively exploited?
It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. That can change: unexploited CVEs regularly get weaponized months after disclosure, which is why patching on your normal cadence matters.
What fixes CVE-2026-34480?
Update Apache log4j to version 2.25.4 or later. Fixed-version data from NVD; the vendor advisory linked on this page has the details.
Which products are affected by CVE-2026-34480?
Apache Log4j.
Can I ask my own AI about CVE-2026-34480?
Yes. This page includes a free, ready-to-paste AI prompt with CVE-2026-34480's key facts: severity, CVSS, CISA KEV status, and the affected products. Copy it into Claude, ChatGPT, or Copilot for a triage plan.
Scope and sources
- Affected products
- Authoritative references
Every Microsoft CVE and the patches that fix it, ranked by real-world risk: the Microsoft Patch Tracker. The full searchable CVE reference: CVE and vulnerability management.