Tungsten Automation Knowledge

Log4net.dll in Kofax Analytics for Capture (KAFC) flagged as a vulnerability

000045883 · General Info · Last Updated: Sep 9, 2026

Question: The log4net.dll installed with KAFC has been flagged as a security vulnerability. The installed version, log4net.dll , is affected by CVE-2018-1285.  Is there a fix for this?

Answer:  This vulnerability is resolved in Analytics for Capture version 2025.4. This release updates log4net to version 3.3, the latest version available at the time of release, which addresses the reported vulnerability.

This update also addresses this vulnerability in TAFC: LINK

You can find the release notes for Analytics for Capture 2025.4 here:

https://docshield.tungstenautomation.com/KAFC/en_US/2025.4-mmbztwz6vb/help/ReleaseNotes/AFC_releasenotes/2025.4/c_introduction_releasenotes.html

NOTE: This issue does not impact Insight. It is isolated to TAFC / KAFC only.

Applies to

ProductVersionBuildEnvironmentHardware
Kofax Analytics for Capture

Sections recovered from body HTML: none detected.

https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/45883 | Article 000045883 | Printed Sep 30, 2026

Back to the article · use your browser's Print command, or save the PDF.