CVE-2021-44228

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 45 articles Published: 2021-12-10

EPSS Score

Source: FIRST.org · 2026-05-24
94.47%
probability
This CVE has a 94.47% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
10.0
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Affected Products

Apache Software Foundation
Apache Log4j2
2.0-beta9

Attack Intelligence

Exploits & PoC

fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

3430
kozmer/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

1852
fox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

439
3 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 94.47%
CVSS v3.1 10.0
Mentions 45
Last Seen Jun 24, 2026

CNA Information

CNA Assigner
apache
CNA Title
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Analyst Note

CVE-2021-44228 (Log4Shell) is the canonical zero-day vulnerability of 2021. It was publicly disclosed on 2021-12-10 and immediately exploited in the wild across thousands of organizations before patches were widely available. Exploitation preceded patch deployment by weeks, and this vulnerability defined zero-day exploitation in 2021-2022. The articles reference immediate, widespread real-world attacks following disclosure.

Threat Actors 69

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 41
apt_group Information theft and espionage 🇨🇳 CN
Turla Group
apt_group Information theft and espionage Russian Federation
Void Arachne
apt_group Information theft and espionage 🇨🇳 CN
APT 29
apt_group Information theft and espionage 🇷🇺 RU
DarkHotel
apt_group Information theft and espionage 🇰🇷 KR
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
Prophet Spider
apt_group UNKNOWN
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
TA800
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
Kinsing
apt_group 🇷🇺 RU
Operation C-Major
apt_group Information theft and espionage 🇵🇰 PK
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
TA505
apt_group Financial gain 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Andariel Group
apt_group 🇰🇷 KR
SideCopy
apt_group Information theft and espionage 🇵🇰 PK
Group 27
apt_group Information theft and espionage 🇨🇳 CN
TeamTNT
apt_group 🇩🇪 DE
TA428
apt_group Information theft and espionage 🇨🇳 CN
GhostR
apt_group 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
TA413
apt_group Information theft and espionage 🇨🇳 CN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
TAG-28
apt_group Information theft and espionage 🇨🇳 CN
Earth Estries
apt_group Information theft and espionage 🇨🇳 CN
HAFNIUM
apt_group Information theft and espionage 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
APT31
apt_group Information theft and espionage 🇨🇳 CN
Returned Libra
apt_group 🇨🇳 CN
POLONIUM
apt_group Information theft and espionage 🇱🇧 LB
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Storm-0530
apt_group 🇰🇵 KP
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Earth Longzhi
apt_group 🇨🇳 CN
UAC-0184
apt_group 🇺🇦 UA
Hezb
apt_group Information theft and espionage 🇱🇧 LB
BRONZE STARLIGHT
apt_group Information theft and espionage 🇨🇳 CN
CyberAv3ngers
apt_group Sabotage and destruction 🇮🇷 IR
Red October
apt_group 🇷🇺 RU
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Test Panda
apt_group 🇨🇳 CN
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
TA2552
apt_group Information theft and espionage 🇮🇷 IR
Magic Kitten
apt_group Information theft and espionage 🇮🇷 IR
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Poisonous Panda
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Scarred Manticore
apt_group Information theft and espionage 🇮🇷 IR
Operation Dragon Castling
apt_group Information theft and espionage 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
PlushDaemon
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime
Dark Partners
apt_group

Triage Info

Decided atMar 05, 2026
Published DateDec 10, 2021