The Ministry of Electronics and Information Technology issued a compliance note Thursday ordering state-run data centers and National Informatics Centre hosting zones to eliminate unpatched Log4j forks before Navratri week, when citizen portals for subsidies, property tax, and festival transit passes historically see traffic jump by double-digit percentages.

What CERT-In already had on file

Indian Computer Emergency Response Team analysts told InfoHandle the directive follows scans that still found vulnerable logging libraries on at least nineteen state-hosted stacks tied to legacy Java middleware. None of those instances were tied to confirmed data exfiltration, but three boards logged outbound callbacks consistent with proof-of-concept exploit chains circulated after the original Log4Shell disclosures.

MeitY’s note does not name the states; CERT-In’s incident desk said attribution waits on state chief information security officers returning signed asset registers due Monday. What is confirmed is that the vulnerable builds were not the upstream Apache release alone—they were vendor forks embedded in e-district workflow engines still running on end-of-life operating systems.

Why festive traffic raises the stakes

State NIC cells host everything from ration-card updates to electricity bill payment iframes that merchants embed during festival sales. Security teams worry that a single compromised logging agent on a shared cluster could let an attacker pivot into databases holding Aadhaar-seeded identifiers even when primary applications were patched years ago.

MeitY tied the deadline to September 26, one week before many states open extended service hours for Navratri registrations. Officials said denial-of-service risk is secondary to silent persistence: attackers who land during a traffic spike can hide noisy scanning inside legitimate peak load.

Who owns the patch window

Liability splits the way it usually does in India’s federated IT setup. States own application code on NIC metal, but NIC supplies baseline images and VPN access for vendor maintainers. MeitY’s order requires both parties to co-sign rollback plans before production restarts—a step several CISOs said they had skipped during earlier emergency Log4j weekends.

Vendor contracts are the gray zone. MeitY reminded states that empanelled auditors must verify forked libraries, not just checkbox “Log4j 2.17 applied” on parent packages. Two systems integrators with active state e-governance deals told InfoHandle they will push hotfixes over the weekend without waiting for full regression suites, a trade-off MeitY said it would tolerate only if boards document accepted functional risk.

Segmentation and logging hygiene

The circular repeats CERT-In guidance to disable JNDI lookups network-wide, segregate administrative VLANs, and forward logs to MeitY’s proposed national coordination center feeds where states already enrolled. Boards that have not enrolled were told to store immutable log copies offline until enrollment completes, because forensic timelines slip when festive outages force log rotation.

Red-team exercises run in Karnataka and Gujarat this month reportedly reached domain controllers from unpatched logging agents on staging clones. Those results are classified, but a MeitY official said the exercises “directly informed” the festive deadline language.

What remains unknown

It is not yet clear whether the Centre will withhold cloud refresh funds for states that miss the September 26 cutoff. MeitY’s note references “progressive compliance” rather than fines. CERT-In would not say if any criminal probe is open; the agency treats the sweep as hygiene unless exfiltration is proven.

Operators also asked whether containerized microservices on state clouds inherit the same fork problem. MeitY said image scanners must include nested JAR manifests—a requirement some smaller states lack tooling to enforce.

Next steps for CISOs

State boards must upload patch attestations to the Cyber Swachhta Kendra portal and schedule joint calls with NIC field engineers before taking citizen payment modules out of maintenance mode. Retail banks that proxy bill-pay traffic through state gateways said they will monitor anomaly scores more tightly during the first Navratri weekend even if attestations arrive on time.

For citizens, officials emphasized that no breach has been confirmed and that UPI rails themselves are separate from these Java stacks. The risk is concentrated on browser sessions that pass through older state portals—exactly the sessions festival weeks amplify.

How states are sequencing downtime

Telangana and Uttar Pradesh boards told InfoHandle they will rotate citizen modules in maintenance pairs so at least one payment channel stays live while logging agents restart. Smaller northeastern states with single-cluster setups may face longer read-only windows; MeitY said it will prioritize NIC engineers for those sites if attestations show good-faith progress by midweek.

Insurance pools covering cyber incidents for public-sector undertakings also asked for copy-of-patch receipts before renewing annual premiums—a commercial pressure that may move laggard states faster than the ministry note alone.