# Security response center

Companies of all sizes are facing heightened cyber security threats in response to state actors, increasing supply chain attacks and open source vulnerabilities. Keeping customers informed, enabled and protected is Sumo Logic’s highest priority.

## Recent security threats

### MongoDB – MongoBleed Server Vulnerability+
**January 2, 2026**  
Sumo Logic is aware of the recently disclosed MongoBleed vulnerability (CVE-2025-14847) affecting multiple MongoDB Server versions. After a thorough review of our systems, we have confirmed that Sumo Logic is not impacted as no MongoDB services were and currently are not actively running. No customer action is required at this time.

### Remote Code Execution (RCE) Vulnerabilities in React and Next.js+
**December 4, 2025**  
Sumo Logic is aware of the recently disclosed Remote Code Execution (RCE) vulnerabilities affecting the react-server and Next.js frameworks (CVE-2025-55182 and CVE-2025-66478). After a thorough review of our systems, we have confirmed that Sumo Logic is not impacted, as the affected components are not used within our environment. No customer action is required at this time.

### Gainsight Salesforce Incident+
**November 24, 2025**  
Sumo Logic is aware of Gainsight’s security incident related to their Salesforce-connected applications. After a thorough investigation, we have determined that there is no impact to Sumo Logic and no action is required from our customers at this time. We will continue to monitor and update as appropriate.

### Cisco ASA RCE and Privilege Escalation+
**September 29, 2025**  
Sumo Logic is aware of the new RCE and privilege escalation vulnerabilities in Cisco ASA (CVE-2025-20333 and CVE-2025-20362). Following a review of our system, we have confirmed that Sumo Logic is not affected by the Cisco ASA vulnerabilities, as this product is not part of our environment. No customer action is required.

### “Shai-Hulud” NPM Supply Chain Worm+
**September 24, 2025**  
Sumo Logic is aware of the recent “Shai-Hulud” worm and npm supply chain attack. Our investigation suggests that Sumo Logic is not impacted by any of the affected packages. We do not utilize or reference any affected npm packages in our products or services. Currently, no action is required from our customers, but we will continue to monitor and update as appropriate.

### Salesloft Drift Breach+
**September 2, 2025**  
Sumo Logic is aware of the recent Salesloft Drift breach. After a thorough investigation, we have determined that Sumo Logic is not impacted, as our products and services do not use Drift. Our current assessment is that no action is required from our customers, but we will continue to monitor and update as appropriate.

### Microsoft SharePoint Zero Day Exploit a.k.a Toolshell vulnerability and Cisco ISE Critical API vulnerability+
**July 23, 2025**  
Sumo Logic is aware of the recent zero-day in Microsoft SharePoint a.k.a. Toolshell (CVE-2025-53770) and Cisco ISE Critical API vulnerabilities ( [CVE-2025-20281](https://thehackernews.com/2025/06/critical-rce-flaws-in-cisco-ise-and-ise.html), [CVE-2025-20337](https://thehackernews.com/2025/07/cisco-warns-of-critical-ise-flaw.html), [CVE-2025-20282](https://thehackernews.com/2025/06/critical-rce-flaws-in-cisco-ise-and-ise.html)). After a thorough investigation, we have determined Sumo Logic is not impacted, as our products and services do not use these tools/technologies. Our current assessment is that no action is required from our customers, but we will continue to monitor and update as appropriate.

### Oracle Cloud Server Breach+
**April 8, 2025**  
Sumo Logic is aware of the recent Oracle Cloud server data breach. Following our initial investigation and system review, we have confirmed that Sumo Logic is not impacted, as we do not use Oracle’s Cloud platform or SSO/identity management products. At this time, there is no impact on our customers, and no action is required. We will continue to monitor the situation and share updates as necessary.

### Ingress-nginx RCE a.k.a IngressNightmare+
**April 4, 2025**  
Sumo Logic is aware of the unauthenticated remote code execution vulnerability in **Ingress-nginx** Controller ( [CVE-2025-1974](https://nvd.nist.gov/vuln/detail/CVE-2025-1974)). After a thorough investigation, we have determined that Sumo Logic is not affected by the vulnerability. At this time, no action is needed from our customers. However, we will continue to monitor the situation and provide updates as appropriate.

### Github Tj-actions+
**March 20, 2025**  
Sumo Logic is aware of the **tj-actions/changed-files** supply chain attack ( [CVE-2025-30066](https://nvd.nist.gov/vuln/detail/cve-2025-30066)), Our extensive investigation suggests that Sumo Logic is not impacted by the compromised tj-action/changed-files. Our current assessment is that no action is required from our customers, but we will continue to monitor and update as appropriate.

### Linguistic Lumberjack: Fluent Bit+
**May 23, 2024**  
On May 20, 2024, Tenable Research [discovered](https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323) a critical memory corruption vulnerability dubbed Linguistic Lumberjack in Fluent Bit (CVE-2024-4323), a core component in the monitoring infrastructure of many cloud services. Sumo Logic has updated all applicable systems to ensure we are not vulnerable and is continuing to monitor our corporate security posture as well as our third-party vendors to ensure they are dealing with the situation as appropriate.

From an open source perspective, although by default none of our solutions are exposed to the internet, some do leverage the impacted versions of Fluent Bit. We have released updated versions in those instances. See below for details.

- Tailing sidecar operator version [0.13.0](https://github.com/SumoLogic/tailing-sidecar/releases/tag/v0.13.0) contains the fix.
- Kubernetes Collection Helm Chart [v4.7.1](https://github.com/SumoLogic/sumologic-kubernetes-collection/releases/tag/v4.7.1) contains the above fix.
- Kubernetes Collection Helm Chart [v3.19.3](https://github.com/SumoLogic/sumologic-kubernetes-collection/releases/tag/v3.19.3) contains the above fix and a separate upgrade to Fluent Bit.
- No upgrades available for Kubernetes Collection Helm Chart version 2. Support for this version ended on 2023-07-20. Customers are encouraged to upgrade to [v4.7.1](https://github.com/SumoLogic/sumologic-kubernetes-collection/releases/tag/v4.7.1).
- No upgrades available for Helm Operator. An upgrade to version 4 of the Helm Chart (where there’s no Fluent Bit) is in progress.

We will continue to monitor and update as appropriate.

### STATUS UPDATE November 20, 2023 – 3:30 PM PST+
**November 20, 2023**
**Update: Sumo Logic Security Incident**  
To our valued customers:

We want to provide you with an update on Sumo Logic’s recent security incident. We take the safety and reliability of our platform seriously. This is why we took immediate action to secure our platform as soon as we detected a potential security incident, including the recommendation to rotate all credentials.

We are grateful to share that the diligent investigation led by our security and engineering teams uncovered no proof of customer data impact and no threat of customer data impact present. These findings were verified by third-party forensic experts and the investigation of this incident is now complete and closed.

We remain committed to providing all of our customers with secure and reliable digital experience and are doing everything we can to emerge safer from this incident. To that end, we will be undertaking additional evaluation to learn from this incident and identify any measures or modifications to prevent future incidents.

As we have done throughout this process, we encourage you to keep an eye on the [Security Response Center](/content/solutions/security/response-center/index.html) where we have posted pertinent updates. We also would like to provide you with additional tools and information.

### FURTHER STEPS YOU CAN TAKE

While this investigation is complete and closed, and there is no proof of customer data impact and no threat of customer data impact present, Sumo Logic is providing the Indicators of Compromise (IOCs) and supporting documentation so customers can inspect their own environments, which we recommend.

### Indicators of Compromise

34.201.113.45  
66.225.222.68  
159.223.118.253  
54.183.5.235  
34.207.95.146  
44.203.0.45  
45.154.98.33  
18.189.57.10  
185.220.101.56  
34.238.239.207  
185.220.101.58  
45.76.10.28

### How to Inspect Your Own Environments

As we formally close this investigation, we want to share some of the techniques we used internally, leveraging the Sumo Logic platform to further guide you in further inspecting your environments and ensuring your security posture.

We used our own solutions within Sumo Logic. In this particular instance, we used both our Cloud SIEM to search our environment for Indicators of Compromise (IOCs) and malicious IPs. In addition, we also used our Cloud Infrastructure Security (CIS) solution for enterprise audit activities such as access key creation, deletion and active vs. inactive. Below is a sample query you can run within your Sumo Logic instance. This will return any source categories where the IOCs are present and will show you where to do further investigation.

### Example Search in Sumo Logic

```
_sourcecategory=* ("34.201.113.45" or "66.225.222.68" or "159.223.118.253" or "54.183.5.235" or "34.207.95.146" or "44.203.0.45" or "45.154.98.33" or "18.189.57.10" or "185.220.101.56" or "34.238.239.207" or "185.220.101.58" or "45.76.10.28")
| timeslice 1m
| parse regex "(?<ioc_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" multi
| where ioc_ip in ("34.201.113.45","66.225.222.68","159.223.118.253","54.183.5.235", "34.207.95.146", "44.203.0.45", "45.154.98.33", "18.189.57.10", "185.220.101.56", "34.238.239.207", "185.220.101.58", "45.76.10.28")
| count _timeslice, _sourcecategory, ioc_ip
```

If you have questions about this guidance, don’t hesitate to get in touch with our customer support team at [https://support.sumologic.com/support/s/](https://support.sumologic.com/support/s/)

Thank you for your patience and understanding throughout this process. We look forward to continuing to help our customers turn insights into action and deliver reliable and secure digital experiences.
