This article addresses security vulnerability CVE-2026-49844 identified in DX UIM 23.4 CU8 and earlier versions, caused by improper JSON serialization in Apache Log4j
DX UIM 23.4 (all CU levels prior to CU9)
This issue is targeted to be fixed in UIM 23.4 CU9 (planned release mid-September 2026). All Log4j components will be upgraded to the latest non-vulnerable version 2.26.1 in this release. Please subscribe to this article for further updates.
For steps to download releases, visit . To contact support for additional queries, see Contact Broadcom Support.