References https://blog.cloudflare.com/zh-cn/inside-the-log4j2-vulnerability-cve-2021-44228/ https://www.anquanke.com/post/id/262668 https://www.secrss.com/articles/37160 https://nic.nwupl.edu.cn/wlaq/yjtz/89611.htm https://stack.chaitin.com/vuldb/detail/fcc63ba8-3aaa-4c64-bff5-98332c3d2f3f https://www.pa55w0rd.online/log4j/ https://zhuanlan.zhihu.com/p/443689489 https://www.green-computing.com/official2/cn/newsevents/news_is_20220103.html https://etnc.gduf.edu.cn/info/1034/1404.htm https://developer.aliyun.com/article/888688 https://github.com/Goqi/ELong https://github.com/merlinepedra25/AttackWebFrameworkTools-5.0 https://www.cnblogs.com/hzhsec/p/19418078 https://www.cnblogs.com/doris5/articles/19918223 https://www.cnblogs.com/M0urn/articles/17761205.html
Related VulnerabilitiesPoCCVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header SpoofingPoCapache-livy-logs: Apache Livy - Logs ExposedApache Log4j2 远程代码执行漏洞(CVE-2021-44228)PoCCVE-2026-41042: Apache Gravitino < 1.2.1 - Unauthenticated Remote Code ExecutionPoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposurePoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassApache IoTDB 认证绕过与远程代码执行漏洞PoCfastly-debug-headers: Fastly CDN Debug Headers ExposurePoCCVE-2025-68493: Apache Struts XWork - XML External Entity InjectionPoCCVE-2024-42323: Apache HertzBeat < 1.6.0 - SnakeYAML Deserialization Remote Code ExecutionPoCCVE-2025-54988: Apache Tika - XXE InjectionPoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials