OVERVIEW CVE-2026-40021 affects Apache Log4net versions prior to 3.3.0, specifically impacting the XmlLayout and XmlLayoutSchemaLog4J components. The vulnerability stems from failure to sanitize XML 1.0-forbidden characters in MDC (Mapped Diagnostic Context) property keys and values, as well as the identity field. When these fields contain attacker-influenced data with invalid XML characters, serialization exceptions occur, causing affected log events to be silently dropped from audit trails. SEVERITY This vulnerability carries a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. The primary impact is integrity-based, as attackers can selectively suppress log records to conceal malicious activity or compromise audit trail completeness. While the attack complexity is low and the vulnerability is easily exploitable, the scope remains unchanged with no confidentiality or availability impacts from the vulnerability itself. The EPSS score of 0.0025 indicates this is not currently a widespread threat. EXPLOITATION STATUS There is no evidence of active exploitation, as this vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code availability has been reported. Community attention remains minimal given the low EPSS score and specialized nature of the attack. Organizations should prioritize patching based on their use of Log4net's XML layout configurations and exposure to untrusted input sources.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.0CPE matchmatch criteria | cpe:2.3:a:apache:log4net:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Apr 10, 2026CVE-2026-40021: Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Apr 10, 2026