CVE-2021-44228

CVSS 10.0 · CRITICAL
Used in ransomware
Known ransomware association per CISA
Exploited in the wild
Remediation overdue by 1683 days
17 public PoCs
Proof-of-concept code linked in references
EPSS p100
Higher than 100% of all CVEs — imminent exploitation likely.
Patch available
Vendor advisory or patch linked

Published 12/10/2021 · updated 2/20/2026 · CWE-20, CWE-400, CWE-502, CWE-917

Share
Get asset-aware triage

Summary

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS 10.0CRITICAL

10.0 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS exploitation probability

94.4%

Percentile p100 Higher than 100% of all CVEs — imminent exploitation likely.

Affected products

143 vendor/product entries
  • Siemens 6bk1602 0aa12 0tp0 Firmware< 2.7.0
  • Siemens 6bk1602 0aa22 0tp0 Firmware< 2.7.0
  • Siemens 6bk1602 0aa32 0tp0 Firmware< 2.7.0
  • Siemens 6bk1602 0aa42 0tp0 Firmware< 2.7.0
  • Siemens 6bk1602 0aa52 0tp0 Firmware< 2.7.0
  • Apache Log4j≥ 2.0.1 and < 2.3.1
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Dec 10, 2021 · Added to CISA KEV catalog
  2. Dec 10, 2021 · Disclosed / published in NVD
  3. Dec 24, 2021 · CISA remediation deadline
  4. Feb 20, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 60 days ago
  • CVE.org· no data
  • FIRST EPSS· 60 days ago
  • CISA KEV· 46 days ago
  • OSV· 57 days ago

Listed in CISA KEV

Added 2021-12-10 · Remediation overdue by 1683 days · used in known ransomware campaigns.

References

Patches & mitigations2
Vendor & CERT advisories6
Proof-of-concept / exploit17

Unlock the full report

See how CVE-2021-44228 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.