CVE-2021-44228
Apache Log4j JNDI remote code execution
Log4Shell. A logged string can trigger a JNDI lookup and remote code execution. CISA KEV lists it, with known ransomware use.
- CVSS
- 10
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Class
- RCE
- Status
- Active Exploitation
- KEV
- Listed in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Log4j 2
- Affected
- Log4j 2.0-beta9 through 2.14.1 are the classic vulnerable range. 2.15.0 did not close the broader JNDI issue set tracked in follow-up CVEs.
- Fixed
- 2.17.1 for Java 8, 2.12.4 for Java 7, and 2.3.2 for Java 6. Confirm the line against the Apache Log4j security page before upgrading.
- Published
- 10 Dec 2021
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2021-44228, known as Log4Shell, is a remote code execution flaw in Apache Log4j 2. Message lookup substitution could treat attacker-controlled log data as a JNDI reference and load code from an LDAP server or another JNDI endpoint.
NVD scores the issue 10.0 and associates it with CWE-917, CWE-20, CWE-502, and CWE-400. CISA added it to the KEV catalog on 10 December 2021 and records known ransomware use. This page marks Active Exploitation on that basis. It was not a silent pre-advisory zero-day in the sense used on this site, so the 0-day flag stays off.
The first vendor fix, 2.15.0, did not end the JNDI problem. Later CVEs covered remaining lookup behavior. The Apache security page is the source for the recommended upgrade lines: 2.17.1, 2.12.4, and 2.3.2, depending on the Java version.
ThreatWire does not host exploit payloads, gadget chains, or scanning commands for this CVE.