Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40021

21
FAUCET Score

OVERVIEW CVE-2026-40021 affects Apache Log4net versions prior to 3.3.0, specifically impacting the XmlLayout and XmlLayoutSchemaLog4J components. The vulnerability stems from failure to sanitize XML 1.0-forbidden characters in MDC (Mapped Diagnostic Context) property keys and values, as well as the identity field. When these fields contain attacker-influenced data with invalid XML characters, serialization exceptions occur, causing affected log events to be silently dropped from audit trails. SEVERITY This vulnerability carries a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. The primary impact is integrity-based, as attackers can selectively suppress log records to conceal malicious activity or compromise audit trail completeness. While the attack complexity is low and the vulnerability is easily exploitable, the scope remains unchanged with no confidentiality or availability impacts from the vulnerability itself. The EPSS score of 0.0025 indicates this is not currently a widespread threat. EXPLOITATION STATUS There is no evidence of active exploitation, as this vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code availability has been reported. Community attention remains minimal given the low EPSS score and specialized nature of the attack. Organizations should prioritize patching based on their use of Log4net's XML layout configurations and exposure to untrusted input sources.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.0CPE matchmatch criteria
cpe:2.3:a:apache:log4net:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.75%
Probability of exploitation in next 30 days
EPSS Percentile
51.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0075 is in the 32nd percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

nugetpatch availablevia ghsa
Product: log4netFixed in: 3.3.0
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

nugetGHSA-4f7c-pmjv-c25wmedium

Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters

Apr 10, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10908.html

CVE-2026-40021: Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters

Apr 10, 2026

References

openwall.com / lists/oss-security/2026/04/10/11
Mailing ListThird Party Advisory
github.com / apache/logging-log4net/pull/280
Issue Tracking
lists.apache.org / thread/q8otftjswhk69n3kxslqg7cobr0x4st7
Mailing ListVendor Advisory
logging.apache.org / cyclonedx/vdr.xml
Product
logging.apache.org / log4net/manual/configuration/layouts.html
Product
logging.apache.org / security.html
Vendor Advisory