logo

Log4Shell: Critical Severity Apache Log4j Remote Code Execution Being Actively Exploited

ID: 493e53e8-203f-5aff-b255-67104d47336c

STIX ID: report--493e53e8-203f-5aff-b255-67104d47336c

Feed Name: Kudelski Security

Threat Score
95/100

Date Published: 2021-12-10

Date Updated: 2026-07-24

...
...

Executive Summary: This advisory details the critical Log4j (Log4Shell) vulnerability enabling remote code execution via JNDI/LDAP lookups, describes incomplete fixes in 2.15.0 and subsequent patches (2.16.0/2.17.0), documents proof-of-concept exploit code and bypasses, reports active exploitation by nation-state and financially motivated actors (including ransomware deployments), and recommends urgent patching or removal of JndiLookup and other mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.