2.15.0 fix was insufficient and only reduces impact to a DoS vulnerability. Fix is in 2.16.0. Unifi already fixed, Graylog seemingly incoming: https://github.com/Graylog2/graylog2-server/pull/11786#issuecomment-994715935
This is being reported on as an info disclosure, too: https://arstechnica.com/information-technology/2021/12/patch-fixing-critical-log4j-0-day-has-its-own-vulnerability-thats-under-exploit/
Elastic products unaffected: https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476
All related bugs have been fixed.