logo

Log4Shell Meltdown: How to protect your cloud from this critical RCE threat

ID: 25309790-f674-50a4-8a39-acdf1de1ca9c

STIX ID: report--25309790-f674-50a4-8a39-acdf1de1ca9c

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2021-12-10

Date Updated: 2026-05-01

...
...

**Executive summary:** Log4Shell (CVE-2021-44228) is a critical remote-code-execution vulnerability in the widely used Java logging library Log4j that allows attackers to trigger JNDI lookups via crafted log data, leading to immediate server takeover; the report describes widespread exposure (Wiz cites ~89% of environments), evidence of exploitation in the wild, recommended mitigations (upgrade to 2.15.0+, use -Dlog4j2.formatMsgNoLookups=True as a temporary measure), and detection/remediation guidance using Wiz's tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.