
Log4Shell
December 2021 remote-code-execution flaw in the Apache Log4j Java logging library.
Log4Shell, the December 2021 remote-code-execution flaw in Apache Log4j, is the reference case behind the EU Cyber Resilience Act's 24-hour reporting duty, which began enforcing on 11 September 2026.
Last refreshed: 22 September 2026
Timeline for Log4Shell
Cyber Resilience Act starts its clock
European Tech SovereigntyBackground
Log4Shell (CVE-2021-44228) is a critical remote-code-execution vulnerability disclosed in December 2021 in Apache Log4j, a widely embedded Java logging library. Because Log4j sits inside thousands of downstream products rather than being sold directly, the flaw became a reference case for software supply-chain risk and for regulation that puts reporting duties on manufacturers rather than on the open-source maintainers whose code those products embed.
It is the worked example behind the EU Cyber Resilience Act's incident-reporting duty. Lowdown's coverage of the Act's 11 September 2026 reporting start cites Log4Shell as the gap that duty closes: a flaw sat inside thousands of commercial products for months and no law required anyone to tell EU authorities quickly .