CVE-2021-44228
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
45 articles
Published: 2021-12-10
EPSS Score
Source: FIRST.org · 2026-05-24
94.47%
probability
This CVE has a 94.47% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS v3.1
Source: VulnerabilityLookup (CIRCL)10.0
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
VulnerabilityLookup (CNA)Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Affected Products
Apache Software Foundation
Apache Log4j2
2.0-beta9
Attack Intelligence
CWE-20
· Improper Input Validation
CWE-400
· Uncontrolled Resource Consumption
CWE-502
· Deserialization of Untrusted Data
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-707
· Improper Neutralization
CWE-74
· Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-77
· Command Injection
CWE-913
· Improper Control of Dynamically-Managed Code Resources
CWE-917
· Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Exploits & PoC
fullhunt/log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
3430
kozmer/log4j-shell-poc
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
1852
fox-it/log4j-finder
Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)
439
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Signal Intelligence
Confidence
95%
EPSS
94.47%
CVSS v3.1
10.0
Mentions
45
Last Seen
Jun 24, 2026
CNA Information
CNA Assigner
apache
CNA Title
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Analyst Note
CVE-2021-44228 (Log4Shell) is the canonical zero-day vulnerability of 2021. It was publicly disclosed on 2021-12-10 and immediately exploited in the wild across thousands of organizations before patches were widely available. Exploitation preceded patch deployment by weeks, and this vulnerability defined zero-day exploitation in 2021-2022. The articles reference immediate, widespread real-world attacks following disclosure.
Threat Actors 69
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
Turla Group
apt_group
Information theft and espionage
Russian Federation
Void Arachne
apt_group
Information theft and espionage
🇨🇳 CN
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
DarkHotel
apt_group
Information theft and espionage
🇰🇷 KR
WIZARD SPIDER
apt_group
Financial gain
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
FIN7
apt_group
Financial crime
🇷🇺 RU
Cron
apt_group
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
EMISSARY PANDA
apt_group
Information theft and espionage
🇨🇳 CN
Prophet Spider
apt_group
UNKNOWN
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
Leviathan
apt_group
Information theft and espionage
🇨🇳 CN
TA800
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Kinsing
apt_group
🇷🇺 RU
Operation C-Major
apt_group
Information theft and espionage
🇵🇰 PK
ELECTRUM
apt_group
Information theft and espionage
🇷🇺 RU
TA505
apt_group
Financial gain
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Andariel Group
apt_group
🇰🇷 KR
SideCopy
apt_group
Information theft and espionage
🇵🇰 PK
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
TeamTNT
apt_group
🇩🇪 DE
TA428
apt_group
Information theft and espionage
🇨🇳 CN
GhostR
apt_group
🇨🇳 CN
SideWinder
apt_group
🇮🇳 IN
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
TA413
apt_group
Information theft and espionage
🇨🇳 CN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
Earth Estries
apt_group
Information theft and espionage
🇨🇳 CN
HAFNIUM
apt_group
Information theft and espionage
🇨🇳 CN
Fox Kitten
apt_group
Information theft and espionage
🇮🇷 IR
APT31
apt_group
Information theft and espionage
🇨🇳 CN
Returned Libra
apt_group
🇨🇳 CN
POLONIUM
apt_group
Information theft and espionage
🇱🇧 LB
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Storm-0530
apt_group
🇰🇵 KP
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Earth Longzhi
apt_group
🇨🇳 CN
UAC-0184
apt_group
🇺🇦 UA
Hezb
apt_group
Information theft and espionage
🇱🇧 LB
BRONZE STARLIGHT
apt_group
Information theft and espionage
🇨🇳 CN
CyberAv3ngers
apt_group
Sabotage and destruction
🇮🇷 IR
Red October
apt_group
🇷🇺 RU
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Test Panda
apt_group
🇨🇳 CN
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
TA2552
apt_group
Information theft and espionage
🇮🇷 IR
Magic Kitten
apt_group
Information theft and espionage
🇮🇷 IR
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Poisonous Panda
apt_group
Information theft and espionage
🇨🇳 CN
Operation Shadow Force
apt_group
🇨🇳 CN
Scarred Manticore
apt_group
Information theft and espionage
🇮🇷 IR
Operation Dragon Castling
apt_group
Information theft and espionage
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
PlushDaemon
apt_group
Information theft and espionage
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Dark Partners
apt_group
Triage Info
Decided atMar 05, 2026
Published DateDec 10, 2021