We have some breaking news. A potential RCE in Apache #Log4J 2 (yes, really) appears to have proofs-of-concept. We have the details, the initial bug report, and mitigation recommendations. We are verifying the PoCs currently.
https://discourse.ifin.network/t/log4j2-allowlist-bypass-could-allow-for-rce/788