This past Thursday, December 9th, a 0-day exploit in the Java logging library, log4j (version 2) was discovered. This vulnerability results in Remote Code Execution by logging a certain string.
“By chaining this group of vulnerabilities together, an attacker could potentially achieve remote code execution which could ... vulnerability in Apache Log4j that was discovered in late 2021.