Skip to main content

Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass vulnerabilities

1 published alerts for Apache Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass.

Microsoft MSRC

CVE-2026-34477

TLS configuration vulnerability

Apache Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass (CVE-2026-34477) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.