Apache Log4j 2’s JNDI lookup feature enabled the critical Log4Shell remote-code-execution vulnerability, tracked as CVE-2021-44228. An attacker could cause a vulnerable application to log a crafted string that triggers a lookup to an attacker-controlled LDAP or other JNDI service, potentially leading to arbitrary code execution under the application’s privileges. The issue affected Log4j 2 versions from 2.0-beta9 through 2.14.1 and created broad exposure because Log4j is widely embedded in Java software and services.
Organizations should identify direct and transitive Log4j dependencies, upgrade to a supported remediated release appropriate to their Java runtime, and verify that deployed artifacts—not only build manifests—no longer contain vulnerable log4j-core versions. SLF4J itself is not vulnerable: it is a logging facade and does not perform Log4j’s JNDI message lookups, though applications using SLF4J can remain exposed when their selected logging backend is vulnerable Log4j 2. Internet-facing Java services and vendor-supplied products should be prioritized for patching, monitoring, and vendor confirmation.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Tenable published Nessus plugin 341265 to identify missing Unity Linux updates for wildfly-security-manager associated with Log4Shell. The local check relies on self-reported installed package versions rather than actively testing exploitability.
Unity Linux published advisory UTSA-2026-031619, providing a security update for wildfly-security-manager that addresses CVE-2021-44228 on affected Unity Linux releases.
CVE-2021-44228, known as Log4Shell, was published as a critical Apache Log4j2 log4j-core JNDI injection vulnerability that can allow remote code execution when attackers control logged data and message lookup substitution is enabled.
Apache Log4j 2.15.0 disabled the affected behavior by default, while versions 2.16.0, 2.12.2, 2.12.3, and 2.3.1 completely removed the affected functionality.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.