logo

CVE-2021-44228: Log4j2 0-day Vulnerability

ID: 4717d113-4240-5e5c-a21b-8bd9fff4471f

STIX ID: report--4717d113-4240-5e5c-a21b-8bd9fff4471f

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Apache Log4j (CVE-2021-44228) remote code execution advisory:** A critical RCE in Log4j versions 2.0-beta9 through 2.14.1 lets attackers trigger JNDI lookups to load remote code; Zscaler observed in‑the‑wild exploit attempts and urges immediate patching to 2.17.1 (or 2.12.2 for Java 7) or removal of the JndiLookup class, provides detection commands and vulnerable hashes, and has deployed signatures (Apache.Exploit.CVE-2021-44228) to block attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.