CISA KEV
Date Added
Dec 10, 2021
Patch Due
Dec 24, 2021
Used in ransomware campaigns
Required Action
For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.