GFI Software
GFI Software has released an update to Kerio Connect (9.3.1 p2) that fixes the Log4j vulnerability, formally named CVE‑2021‑44228. All Kerio Connect server administrators are strongly advised to install the patch as soon as possible to prevent possible exploitation of the vulnerability. If you are unable to update, you should disable the “Chat” feature to prevent possible exploitation. The patched version is available for download at https://upgrade.gfi.com/check/kerio-connect/931-patch-2.
In quick response to the Log4j vulerability, the GFI LanGuard vulnerability database has been updated as well. The vulnerability scan now reveals the Log4j vulnerability on both Windows and Linux systems. The database is updated automatically, or you can download it yourself in the solution’s user interface or just check if you have version 251. If you don’t use GFI LanGuard currently but want your systems to be protected against the latest threats, you can download and try GFI Languard’s 30-day free trial version and experience safety for yourself.