Skip to content
You can now search across every topic, entity and event.What's new
Log4Shell
AI-generated illustration
Concept

Log4Shell

December 2021 remote-code-execution flaw in the Apache Log4j Java logging library.

Log4Shell, the December 2021 remote-code-execution flaw in Apache Log4j, is the reference case behind the EU Cyber Resilience Act's 24-hour reporting duty, which began enforcing on 11 September 2026.

Last refreshed: 22 September 2026

Timeline for Log4Shell

#16 11 Sept

Cyber Resilience Act starts its clock

European Tech Sovereignty
View full timeline →

Background

Log4Shell (CVE-2021-44228) is a critical remote-code-execution vulnerability disclosed in December 2021 in Apache Log4j, a widely embedded Java logging library. Because Log4j sits inside thousands of downstream products rather than being sold directly, the flaw became a reference case for software supply-chain risk and for regulation that puts reporting duties on manufacturers rather than on the open-source maintainers whose code those products embed.

It is the worked example behind the EU Cyber Resilience Act's incident-reporting duty. Lowdown's coverage of the Act's 11 September 2026 reporting start cites Log4Shell as the gap that duty closes: a flaw sat inside thousands of commercial products for months and no law required anyone to tell EU authorities quickly .

Common Questions
What was Log4Shell?
Log4Shell was a critical remote-code-execution vulnerability, disclosed in December 2021, in the widely embedded Apache Log4j Java logging library.
Why does the Cyber Resilience Act matter after Log4Shell?
Log4Shell sat inside thousands of commercial products for months with no legal duty to notify EU authorities quickly. The Cyber Resilience Act turns that gap into a binding 24-hour reporting Deadline.Source:
Source Material