CVE-2026-85656: Amazon LOG4J-Cve-2021-44228-Hotpatch
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Affected products
- Amazon LOG4J-Cve-2021-44228-Hotpatch: before 1.3-9.amzn2 (fixed in 1.3-9.amzn2)
Published 2026-09-04. Last modified 2026-09-08.