Great timing. Here in the UK it's a four-day weekend. Can imagine that many affected will see this too late...
It probably is.
I raised the alarm for log4shell internally on December 9th, and then then it was being actively exploited. I know people at other companies who hadn't heard about it, or didn't think it was worth doing anything about, as recently as April.