Skip to content
Weekly Signal
Live intelligence Updated 19 Aug 2026 · 20:27 UTC

Apache, Apple, Bentley +9 more · Log4j, Log4j2, Xcode +140 more

CVE-2021-44228

Apache Log4j2 Remote Code Execution Vulnerability

Recommended action

Treat this as an immediate remediation priority. For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

View response plan
CVSS10.0
EPSS100.0%
KEVYes
ExploitationConfirmed exploitation
PatchPatch or guidance available ↓

Assessment

Why it matters

CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 100.0%; technical severity is CVSS 10.0.

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Who should care

  • Teams operating Log4j, Log4j2, Xcode +140 more
  • Vulnerability and exposure management teams
  • Security operations teams monitoring exploitation activity

Response plan

What I would do

  1. Confirm whether Log4j, Log4j2, Xcode +140 more is present in the environment.
  2. Identify affected versions and establish whether vulnerable services are exposed or reachable.
  3. For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
  4. Review relevant security telemetry for evidence of attempted or successful exploitation.
  5. Document the remediation decision and track it to verified completion.

Vendor remediation

Patch and remediation links

Use the vendor source below to confirm the correct fixed version, package or mitigation for your affected product.

Technical details

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-20
Affected versions
Apache Log4j (Version: 2.0); Apache Log4j2; Apple Xcode (End Excluding: 13.3); Bentley Synchro (Start Including: 6.1, End Excluding: 6.2.4.2); Bentley Synchro 4d (End Excluding: 6.4.3.2); Cisco Advanced Malware Protection Virtual Private Cloud Appliance (End Excluding: 3.5.4); Cisco Automated Subsea Tuning (Version: 02.01.00); Cisco Broadworks (Version: -)
Published
10 December 2021
Attack vector
Network
Privileges required
None
User interaction
None

Signal timeline

  1. CVE published
  2. Added to CISA KEV
  3. Latest EPSS score: 100.0%
  4. Signal calculated at 88

External references

Live public intelligence This assessment combines public-source evidence. Validate the affected product, version and exposure against your own environment before making a risk decision.