PT-2026-86208 · Amazon · Log4J-Cve-2021-44228-Hotpatch

CVE-2026-85656

·

Published

2026-09-04

·

Updated

2026-09-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-85656: OS command injection in Amazon Linux's log4j hotpatch package (<1.3-9). Local user can execute arbitrary commands as root via crafted Java process path with newlines. CVSS 7.8. Unpatched! If you rely on this https://t.co/USqzEPbRQs #CVE #valtersit #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany #docker #kali

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85656

Affected Products

Log4J-Cve-2021-44228-Hotpatch