Unlike several other competitive monitoring products, NetCrunch does not use the Apache log4j library and is not affected by log4j vulnerability.
Until NetCrunch 10 we were using Java to monitor ESX/ESXi, but the log4j library was not enabled nor used. However, to double-proof your monitoring system, it is recommended to upgrade from older NetCrunch versions (7, 8, 9, or 10) to NetCrunch 11.