logo

Log4j Vulnerability Activity on the HackerOne Platform

ID: f34b8f32-0289-5b0c-b99f-6afc25f966fc

STIX ID: report--f34b8f32-0289-5b0c-b99f-6afc25f966fc

Feed Name: HackerOne Blog

Threat Score
95/100

Date Published: 2024-11-26

Date Updated: 2026-06-11

...
...

This HackerOne post details the severe Log4j vulnerabilities (initially CVE-2021-44228 and the later CVE-2021-45046), explains the technical risk (unauthenticated RCE, CVSS 10), documents active exploitation and high attack volume, summarizes HackerOne submission statistics and customer responses, and provides mitigation and bug-bounty guidance (including upgrading to Log4j 2.16.0 and expanding/incentivizing program scope).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.