Public Disclosure: Unpatched Log4j RCE Flaw in FilteredObjectInputStream, No CVE Assigned
ID: d0d608f2-5058-54de-b9ff-ac93cb88dfc9
STIX ID: report--d0d608f2-5058-54de-b9ff-ac93cb88dfc9
Feed Name: securityonline.info
Researchers disclosed an unpatched Log4j remote code execution vulnerability (August 24, 2026) in FilteredObjectInputStream that allows java.rmi.MarshalledObject payloads to bypass filtering; affected versions include log4j-api 2.11.0–2.26.1 and log4j-core 2.8.0–2.26.1. The technical write-up is public but full exploit code is withheld from the public pending a fix; no CVE or confirmed in-the-wild exploitation yet. Mitigations include applying a serial filter to block the risky class and restricting network access to services that accept serialized log events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
