Forum Discussion

Josh_BP's avatar
Josh_BP
Regular Visitor
2 months ago
Solved

CVE-2026-34478

Not sure if this the right place, but trying to out a solution to CVE-2026-34478. This has to do with a log4j vulnerability. We have an On Prem gateway version 3000.318.11 and still see the 2.25.3 version of the jar files that are being flagged. Is this something Microsoft is aware of and are working on fixing? Can we delete these files with breaking the gateway? Just trying to see if we have any options.

 

Edit: Had wrong Gateway version listed.

  • I think Microsoft has already patched in 3000.310 (March 2026 release). The latest is actually 3000.318 as of early June, so you're pretty far behind at this point.

    Don't delete the JAR files, that'll break things. The only real fix here is upgrading the gateway. It's an in-place upgrade so your existing connections should survive, just do it during a maintenance window to be safe.

1 Reply

  • I think Microsoft has already patched in 3000.310 (March 2026 release). The latest is actually 3000.318 as of early June, so you're pretty far behind at this point.

    Don't delete the JAR files, that'll break things. The only real fix here is upgrading the gateway. It's an in-place upgrade so your existing connections should survive, just do it during a maintenance window to be safe.