Hazard

Is CVE-2021-44228 being exploited?

Ransomware crews are using this

CISA has linked this vulnerability to known ransomware campaigns. Treat any exposed instance as an active incident, not a patching ticket.

Apache Log4j2 Remote Code Execution Vulnerability

Apache · Log4j2

CVSS 10 EPSS 100% 3 public exploits ransomware Fix deadline passed 24 December 2021

What it is

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Why we say that

  • Linked by CISA to known ransomware campaigns
  • EPSS puts exploitation in the next 30 days at 100%
  • 3 public exploits published
  • CISA's federal remediation deadline (2021-12-24) has passed
  • CVSS 10 critical
  • Listed in the CISA Known Exploited Vulnerabilities catalogue

Every line above comes from a named public source. Where the evidence is thin, we say so rather than inventing confidence — see methodology.

What to do

For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

Public exploit code

Indexed from Exploit-DB. Presence of code raises urgency; absence does not mean safety.

What it costs when this goes wrong

This is where UK enforcement meets the vulnerability record. This vulnerability is used in ransomware campaigns; here is what ransomware has cost UK organisations at the regulator.

All UK cases caused by ransomware →