Vulnerability threat dossier

CVE-2021-44228

apachelog4j

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

VTP deterministic threat59.5of 100 · CVSS excluded

VTP analyst assessment

Apache Log4j2 JNDI remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence97%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists Log4Shell as exploited globally. Attacker-controlled data reaching vulnerable Log4j2 lookups can trigger code loaded through LDAP or related JNDI endpoints. Greenbone reports exploit-tooling coverage, not successful exploitation.

Why it matters

  • The affected logging library may be embedded in internet-facing or internal applications.
  • CISA KEV records known ransomware campaign use.

Evidence

2 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The cited press reporting is not relevant to this CVE.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use vulnerable Log4j2 versions, upgrade to a security release or apply Apache mitigation.

AI baseline history (4)
  1. BASELINE ASSESSED
    Apache Log4j2 JNDI remote code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Log4j remote code execution is known exploitedgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Apache Log4j2 remote code executiongpt-5.6-terra · low
  4. BASELINE ASSESSED
    Apache Log4j2 Log4Shell remote code executiongpt-5.6-sol · high

Previous AI priority: HIGH → current: HIGH. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

5publications detected
5underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:5477d73732796ddb34c4daedc8a472251f82dec4ACTIVE
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:660c5a8bf31a00b07278d79f3834cac565b462acRETIRED
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:a3245ac22fbdfa682646d4fa3328850e649e7d6f999276e27ad1da895c6cdfd9ACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:8a15915ac64046879dfa4922f966118474d7af98ACTIVE
Evidence
04

Event history

Threat timeline

  1. 02:3508 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 02:3107 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 16:4226 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  4. 18:1724 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  5. 07:2703 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2021-44228.

  6. 00:0010 Dec
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 2 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 2 CVEs in this pinned revision. 2 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2021-44228CVE-2021-45046
Separate evidence group

Exploit tooling coverage changed for 9 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 9 CVEs in this pinned revision. 9 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2009-4595CVE-2009-4596CVE-2009-4597CVE-2017-5487CVE-2019-4169CVE-2021-31805CVE-2021-44228CVE-2021-45046CVE-2022-24706
Separate evidence group

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

CVE-2018-13379CVE-2019-10068CVE-2019-19781CVE-2020-5902CVE-2021-26855CVE-2021-44228CVE-2023-22515CVE-2024-24919CVE-2024-8190CVE-2024-8963CVE-2024-9380CVE-2025-31161CVE-2026-1731
Separate evidence group
Original

Exploit tooling coverage expanded for 51 CVEs

ProjectDiscovery nuclei-templates added or materially changed exploit-oriented artifacts covering 51 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2015-7501CVE-2018-11714CVE-2018-14839CVE-2018-7282CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-44228CVE-2022-1281CVE-2023-25157CVE-2023-25826CVE-2023-27350CVE-2023-31059CVE-2023-3710CVE-2023-39143CVE-2024-33605CVE-2024-57726CVE-2025-0520CVE-2025-26399CVE-2026-0558CVE-2026-11387CVE-2026-12394CVE-2026-15826CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25895CVE-2026-26217CVE-2026-32255CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-4060CVE-2026-41042CVE-2026-45695CVE-2026-49069CVE-2026-5032CVE-2026-52806CVE-2026-53753CVE-2026-54917CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-61511CVE-2026-64849CVE-2026-6854CVE-2026-69084
Separate evidence group
Original

Nuclei Templates v10.4.7 - Release Notes

New Templates Added: 122 | CVEs Added: 49 | First-time contributions: 23 🔥 Release Highlights 🔥 [CVE-2026-63030] WordPress Core 6.9-7.0.1 - Pre-Auth Batch-Route Confusion ( @slcyber , @mielverkerken , @pdteam , @FLX-0x00 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-60004 ] Gitea <= 1.27.0 - Pre-Auth Remote Code Execution (@0x_Akoko) [critical] 🔥 [ CVE-2026-58455 ] Dockwatch <= 0.6.567 - OS Command Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-56291 ] Balbooa Forms < 2.4.1 - Unauth Arbitrary File Upload ( @nick Vidovic, @0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-56290 ] Page Builder CK <= 3.5.10 - Unauth File Upload ( @panchiko-p , @0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48908 ] Joomla SP Page Builder <= 6.6.1 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-46442 ] Flowise < 3.1.2 - node-custom-function Unauth RCE ( @dhiyaneshdk , @princechaddha ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-44825 ] Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials ( @pdteam , @0x_Akoko) [high] (kev) (vKEV) 🔥 [ CVE-2026-16232 ] Check Point Security Management Server - SmartConsole Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-15409 ] SonicWall SMA1000 - Server-Side Request Forgery ( @dhiyaneshdk , @rapid7 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9282 ] W3 Total Cache <= 2.9.4 - Unauth Arbitrary File Read (@0x_Akoko) [high] (kev) (vKEV) 🔥 [ CVE-2026-8732 ] WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauth Administrator Account Creation ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-8713 ] Avada (Fusion) Builder <= 3.15.3 - Unauth Arbitrary File Deletion (@rool-machine) [critical] (kev) (vKEV) 🔥 [ CVE-2026-6875 ] ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE ( @pdteam , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-3296 ] Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-71334 ] Flowise - Path Traversal ( @theamanrawat ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-68493 ] Apache Struts XWork - XML External Entity Injection ( @pussycat0x ) [high] (kev) (vKEV) 🔥 [ CVE-2025-54988 ] Apache Tika - XXE Injection ( @tx1ee ) [critical] 🔥 [ CVE-2025-6389 ] Sneeit WP Social WordPress Plugin - Unauth RCE via call_user_func ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-2505 ] WordPress Age Gate <= 3.5.3 - Unauth Local File Inclusion ( @pussycat0x ) [critical] (kev) (vKEV) 🔥 [CVE-2024-56511] DataEase < 2.10.4 - Authentication Bypass via Whitelist Path Traversal ( @ChrisJr404 ) [critical] 🔥 [ CVE-2023-34992 ] Fortinet FortiSIEM - Unauth Command Injection ( @Thacien ) [critical] 🔥 What's Changed Bug Fixes Stopped credential-stuffing and token-spray templates from sending their first request when no username, password or token is supplied (PR #16589 , Issue #11238 ). Restored missing matcher and extractor values in four templates that silently no-op'd, including CVE-2021-44228 , CVE-2021-45046 and CVE-2026-42281 (PR #16661 ). Replaced an unsupported RE2 lookahead that stopped home-env-permission.yaml from loading at all (PR #16664 ). Added the missing capture group to three regex extractors (PR #16665 ). Corrected the extractor part in portal-api-ssrf from interactsh to interactsh_request (PR #16667 ). Corrected the DSL variable in thinkphp6-arbitrary-write from status_2 to status_code_2 (PR #16668 ). Unhid two extractors marked internal that nothing consumed (PR #16669 ). Marked the setup-stage matchers in CVE-2025-2075 as internal (PR #16671 ). Removed an AWS access key ID from a reference URL in CVE-2024-51482.yaml (PR #16616 ). Fixed an intrusive tag typo in CVE-2023-34124 .yaml (PR #16675 ). Corrected the id and filename for the IBM DB2 Server template (PR #16688 ). Fixed the severity in directory-listing-no-host-header.yaml (PR #16614 ). Corrected the author field for CVE-2024-23108 (PR #16620 ). Moved CVE-2025-296

CVE-2008-2052CVE-2019-14793CVE-2021-27877CVE-2021-44228CVE-2021-45046CVE-2021-47795CVE-2023-34124CVE-2023-34992CVE-2023-50839CVE-2024-22476CVE-2024-23108CVE-2024-42323CVE-2024-51482CVE-2024-56511CVE-2025-14047CVE-2025-2075CVE-2025-2505CVE-2025-29635CVE-2025-32969CVE-2025-54988CVE-2025-55746CVE-2025-6389CVE-2025-68493CVE-2025-71334CVE-2026-15094CVE-2026-15409CVE-2026-16232CVE-2026-1830CVE-2026-1980CVE-2026-22683CVE-2026-23550CVE-2026-23696CVE-2026-23829CVE-2026-30623CVE-2026-31831CVE-2026-3296CVE-2026-3335CVE-2026-33497CVE-2026-34036CVE-2026-3891CVE-2026-39468CVE-2026-42281CVE-2026-42796CVE-2026-44825CVE-2026-46442CVE-2026-48908CVE-2026-48909CVE-2026-4987CVE-2026-49952CVE-2026-52773CVE-2026-52824CVE-2026-54836CVE-2026-55450CVE-2026-56290CVE-2026-56291CVE-2026-58455CVE-2026-60004CVE-2026-6043CVE-2026-63030CVE-2026-65694CVE-2026-6875CVE-2026-8385CVE-2026-8713CVE-2026-8732CVE-2026-9198CVE-2026-9282
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-20, CWE-400, CWE-502, CWE-917
CPE records
381
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.