What are you doing about it?
With log4j you have a brutal combination of:
1. RCE
2. Exposure
RCE happens frequently but often attackers don't have an easy time getting to the exploitable code. With log4j it's trivial - every app can be owned.
But here are some questions:
1. Why do those apps have the ability to make network requests?
2. For the apps that need to make those requests internally, why aren't those over mTLS?
3. For the apps that need to make them externally, why isn't that going through egress proxying?
4. Why are there credentials spewed all over your environment variables across your services? Are they short lived?
It's actually not super hard to have a worst-case scenario vulnerability like log4j be not that bad for your organization. A bit of hardening and even if something like this happens you're in a good position to wait, monitor, and patch.