StackRadar

CVE-2026-34480

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.010
60th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
269
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

Carried by container images the latest versions of 269 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+34 more2.25.4255
OSV records
GHSA-3pxv-7cmr-fjr4

Charts affected

269 by stars
ChartLatestAffected imagesRadar Score
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
log4j-core@2.14.0
2.25.4

Open the chart page →

2,751
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
featurehub/dacha2:1.9.1c8d5551b5e40
log4j-core@2.20.0
2.25.4
featurehub/edge:1.9.198ad426737f6
log4j-core@2.20.0
2.25.4
featurehub/mr:1.9.1477d8bf771a9
log4j-core@2.20.0
2.25.4

Open the chart page →

8,240
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4

Open the chart page →

11,553
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
log4j-core@2.17.1
2.25.4

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
log4j-core@2.20.0
2.25.4

Open the chart page →

4,679
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
log4j-core@2.20.0
2.25.4

Open the chart page →

3,470
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-core@2.17.1
2.25.4

Open the chart page →

17,284
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
log4j-core@2.17.1
2.25.4

Open the chart page →

3,421
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
log4j-core@2.17.2
2.25.4

Open the chart page →

2,067
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.01 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-core@2.20.0
2.25.4

Open the chart page →

14,130
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-core@2.17.1
2.25.4

Open the chart page →

12,019
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
log4j-core@2.17.1
2.25.4

Open the chart page →

13,479
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
log4j-core@2.17.1
2.25.4

Open the chart page →

2,221
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
log4j-core@2.12.4
2.25.4

Open the chart page →

37,373
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
log4j-core@2.25.2
2.25.4

Open the chart page →

1,916
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
log4j-core@2.23.1
2.25.4

Open the chart page →

1,692
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
log4j-core@2.17.1
2.25.4
treskon/portrait:DEV-latest88e813f22347
log4j-core@2.23.1
2.25.4

Open the chart page →

31,844
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
log4j-core@2.25.3
2.25.4

Open the chart page →

8,158
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
log4j-core@2.24.3
2.25.4

Open the chart page →

7,432
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
log4j-core@2.17.1
2.25.4

Open the chart page →

6,045
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
log4j-core@2.17.1
2.25.4

Open the chart page →

7,529
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
log4j-core@2.11.0
2.25.4

Open the chart page →

4,983
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-core@2.20.0
2.25.4

Open the chart page →

2,406
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-core@2.24.3
2.25.4

Open the chart page →

1,482
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.25.4

Open the chart page →

24,930
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
log4j-core@2.9.1
2.25.4

Open the chart page →

8,063
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.25.4

Open the chart page →

15,970
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-core@2.20.0
2.25.4

Open the chart page →

7,835
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
log4j-core@2.25.2
2.25.4

Open the chart page →

3,188
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-core@2.25.3
2.25.4

Open the chart page →

395
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-core@2.23.1
2.25.4

Open the chart page →

854
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
log4j-core@2.17.2
2.25.4

Open the chart page →

1,413
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-core@2.24.3
2.25.4

Open the chart page →

4,777
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
log4j-core@2.24.3
2.25.4

Open the chart page →

3,217
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-core@2.24.3
2.25.4

Open the chart page →

1,826
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
log4j-core@2.24.2
2.25.4

Open the chart page →

7,603
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
log4j-core@2.24.2
2.25.4

Open the chart page →

1,523
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
log4j-core@2.24.2
2.25.4

Open the chart page →

3,442
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
log4j-core@2.17.1
2.25.4

Open the chart page →

2,099
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
log4j-core@2.20.0
2.25.4

Open the chart page →

1,165
amorphieamorphie0.1.23 of 18See more

amorphie amorphie 0.1.2

3 of the 18 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
log4j-core@2.22.1
2.25.4
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-core@2.20.0
2.25.4
hazelcast/management-center:5.3.2f9d34300d330
log4j-core@2.17.2
2.25.4

Open the chart page →

28,131
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4

Open the chart page →

11,553
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
log4j-core@2.17.1
2.25.4

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
log4j-core@2.17.1
2.25.4
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
log4j-core@2.20.0
2.25.4

Open the chart page →

16,975
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
log4j-core@2.12.4
2.25.4

Open the chart page →

40,238
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
log4j-core@2.17.1
2.25.4

Open the chart page →

14,728
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
log4j-core@2.17.0
2.25.4

Open the chart page →

7,936
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
log4j-core@2.17.2
2.25.4

Open the chart page →

4,145
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.25.4

Open the chart page →

5,806
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
log4j-core@2.17.2
2.25.4

Open the chart page →

13,459

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-courses:latest68ca414f5596
log4j-core@2.24.3
2.25.4
1
folioci/mod-data-export:latest0cc86bf09755
log4j-core@2.25.3
2.25.4
1
folioci/mod-data-export-spring:latestf1d7caf4544b
log4j-core@2.25.3
2.25.4
1
folioci/mod-data-export-worker:latest1ad1811c9b37
log4j-core@2.25.3
2.25.4
1
folioci/mod-data-import-converter-storage:latest3028f333778f
log4j-core@2.17.2
2.25.4
1
folioci/mod-ebsconet:latest3ae8cb99daa3
log4j-core@2.25.2
2.25.4
1
folioci/mod-email:latest79ea8e2e7ebf
log4j-core@2.25.3
2.25.4
1
folioci/mod-eusage-reports:latest15de67587091
log4j-core@2.25.3
2.25.4
1
folioci/mod-feesfines:latestfe3a7049f2fb
log4j-core@2.24.3
2.25.4
1
folioci/mod-inn-reach:latestcc8584e43382
log4j-core@2.19.0
2.25.4
1
folioci/mod-inventory-update:latestba84812b4d58
log4j-core@2.24.3
2.25.4
1
folioci/mod-login:latest88de493f86db
log4j-core@2.24.3
2.25.4
1
folioci/mod-marccat:latest1b57d690d568
log4j-core@2.10.0
2.25.4
1
folioci/mod-ncip:latest8ed83674352b
log4j-core@2.20.0
2.25.4
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
log4j-core@2.24.3
2.25.4
1
folioci/mod-patron:latest5f213acfe2f8
log4j-core@2.24.3
2.25.4
1
folioci/mod-patron-blocks:latestde7318069a67
log4j-core@2.24.3
2.25.4
1
folioci/mod-pubsub:latest0a4fa4ad5d72
log4j-core@2.24.0
2.25.4
1
folioci/mod-rtac:latestc959b2d6142f
log4j-core@2.24.3
2.25.4
1
folioci/mod-sender:latestd88a675dddf0
log4j-core@2.25.2
2.25.4
1
folioci/mod-template-engine:latestd105c585da30
log4j-core@2.24.3
2.25.4
1
folioci/mod-users-bl:latest4e2d96c9340d
log4j-core@2.25.2
2.25.4
1
fonoster/routr:1.0.0-rc52ca65af17cbc
log4j-core@2.11.0
2.25.4
1
fonoster/routr-edgeport:2.13.6d08a8a574a50
log4j-core@2.22.0
2.25.4
1
fonoster/routr-requester:2.13.6e0c823506eb2
log4j-core@2.22.0
2.25.4
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-core@2.13.3
2.25.4
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
log4j-core@2.25.3
2.25.4
1
graylog2/server:2.4.3-38ff28c66e6c1
log4j-core@2.9.1
2.25.4
1
graylog/graylog:6.1.1019de1aff48c2
log4j-core@2.24.1
2.25.4
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
log4j-core@2.25.3
2.25.4
1
gridgain/community:8.9.11d32d182a0e6a
log4j-core@2.20.0
2.25.4
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
log4j-core@2.17.2
2.25.4
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
log4j-core@2.17.2
2.25.4
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
log4j-core@2.17.2
2.25.4
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
log4j-core@2.17.2
2.25.4
1
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-core@2.20.0
2.25.4
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
log4j-core@2.17.0
2.25.4
1
hazelcast/management-center:5.3.2f9d34300d330
log4j-core@2.17.2
2.25.4
1
hmediade/printserver:latest481a552c8e1c
log4j-core@2.17.2
2.25.4
1
iamdorsah/bastillion:v0.1db83a0254d81
log4j-core@2.17.1
2.25.4
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
log4j-core@2.11.2
2.25.4
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
log4j-core@2.11.1
2.25.4
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
log4j-core@2.11.1
2.25.4
1
ibmcom/microclimate-portal:latested5505e5c7ec
log4j-core@2.8.2
2.25.4
1
jacobalberty/unifi:v7.1.664a3616625dda
log4j-core@2.17.2
2.25.4
1
jacobalberty/unifi:5.10.19c409924e2463
log4j-core@2.11.1
2.25.4
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-core@2.17.2
2.25.4
1
just1not2/streama:1.10.48a2305192dec
log4j-core@2.17.1
2.25.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-core@2.20.0
2.25.4
1
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-core@2.20.0
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.