CVE-2026-85656EPSS p64.0%
CVE-2026-85656CVE-2026-85656
Description
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.08% probability of exploitation · percentile 64.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |