CVE-2021-44228CISA KEVEPSS p100.0%

CVE-2021-44228Apache Log4j2 Remote Code Execution Vulnerability

Apache / Log4j2

Description

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Scoring

EPSS100.00% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2021-12-10

(incoming)1

TypeTargetConfidenceTier
KEVEntryApache Log4j2 Remote Code Execution Vulnerabilitykev-cve-2021-442280%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
CVE
Apache APISIX Authentication Bypass Vulnerability
CVE
CVE-2025-29902
CVE
Oracle WebLogic Server Remote Code Execution Vulnerability
CVE
CVE-2025-48913
CVE
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.