diff --git a/eng/versioning/external_dependencies.txt b/eng/versioning/external_dependencies.txt
index bd40c705e6d1..1b8a1ece419d 100644
--- a/eng/versioning/external_dependencies.txt
+++ b/eng/versioning/external_dependencies.txt
@@ -280,6 +280,9 @@ cosmos_org.testcontainers:kafka;1.21.4
cosmos_org.sourcelab:kafka-connect-client;4.0.4
cosmos_io.confluent:kafka-avro-serializer;7.6.0
cosmos_org.apache.avro:avro;1.11.4
+cosmos_org.apache.logging.log4j:log4j-api;2.25.3
+cosmos_org.apache.logging.log4j:log4j-core;2.25.3
+cosmos_org.apache.logging.log4j:log4j-slf4j-impl;2.25.3
# Maven Tools for Cosmos Kafka connector only
# sdk\resourcemanager\azure-resourcemanager\pom.xml
diff --git a/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md b/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md
index 95d5b6501bc3..e278e4a1b379 100644
--- a/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md
+++ b/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md
@@ -9,6 +9,8 @@
#### Bugs Fixed
#### Other Changes
+* Updated `log4j-api`, `log4j-core` and `log4j-slf4j-impl` test dependencies to `2.25.3` to address [CVE-2025-68161](https://github.com/advisories/GHSA-pgxp-9w8h-vfh4) (Apache Log4j: information disclosure via missing TLS hostname verification).
+* Picked up patched versions of `jackson-core` (`2.18.6`) and `netty-codec-http`/`netty-codec-http2` (`4.1.132.Final`) transitively via `azure-cosmos` `4.81.0-beta.1`, addressing [GHSA-72hv-8253-57qq](https://github.com/advisories/GHSA-72hv-8253-57qq), [CVE-2026-33870](https://nvd.nist.gov/vuln/detail/CVE-2026-33870), [CVE-2025-67735](https://nvd.nist.gov/vuln/detail/CVE-2025-67735) and [CVE-2026-33871](https://nvd.nist.gov/vuln/detail/CVE-2026-33871).
### 2.10.0 (2026-05-01)
diff --git a/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml b/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml
index ec496f401860..27828c2f0243 100644
--- a/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml
+++ b/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml
@@ -181,21 +181,21 @@ Licensed under the MIT License.
org.apache.logging.log4j
log4j-slf4j-impl
- 2.17.2
+ 2.25.3
test
org.apache.logging.log4j
log4j-api
- 2.17.2
+ 2.25.3
test
org.apache.logging.log4j
log4j-core
- 2.17.2
+ 2.25.3
test