Only two remediations count — CISA narrows the options on the Log4j2 flaw
For the remote code execution flaw in Apache Log4j2, CISA recognized nothing as remediation except applying updates or removing the affected assets from agency networks. Temporary mitigations were allowed only until updates existed.
Key facts
- CVE IDCVE-2021-44228
- Affected (vendor / product)Apache Log4j2
- CWECWE-20, CWE-400, CWE-502
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2021-12-24 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2021-44228 is a remote code execution flaw in Apache Log4j2, arising where the JNDI functionality fails to guard against endpoints an attacker controls.
- It entered the catalog on 10 December 2021 with remediation due 24 December 2021, and ransomware use is recorded as known.
- The required action allows two remediations and no others: putting the update on, or taking the asset off agency networks.
- Temporary mitigations from emergency directive ED 22-02 are acceptable only until updates become available.
- Among the 1,579 entries without an article within the 1,695 records this site holds as of 2026-09-05, the required action takes forty forms and 889 (56.3%) share one line.
1The instructions have shapes too
The catalog of known exploited vulnerabilities is not merely a list of flaws. Each entry carries a field for the required action, setting out what federal agencies are to do. Most end in one line: apply updates per vendor instructions. This series takes up eight cases where that line was not enough.
2More than half end in that one line
The wording of the required action comes in forty forms only. A majority, 889 entries, share the same line. Against that, twenty-two of the forms appear on between one and four entries, and each of those carries something particular to the flaw it addresses.
3Two, and nothing else
The instruction on this entry closes off the alternatives explicitly.
The word acceptable is doing the work here. Whatever else an agency might devise does not count as remediation. Getting by on a mitigation is an exception permitted only while no update exists.
4Why spell it out
The entry was added on 10 December 2021 with a due date of 24 December: fourteen days. Log4j2 sits inside a great many other pieces of software as a component, so an organization often cannot establish its own exposure by itself. Ransomware use is recorded as known.
In that situation, leaving room for each agency to decide on its own that it has dealt with the problem is itself the danger. Limiting the answer to two is a way of closing that room. The next article takes up an entry that went further and set an order: cut the traffic before you fix anything.
Why it matters
The catalog of known exploited vulnerabilities is a body of instructions as much as a list of flaws. A majority need only the line about applying updates, but where an organization cannot establish its own exposure, the room each agency has to decide for itself that the matter is handled becomes the hazard. Narrowing acceptable remediation to two reads as a design for closing that room.
FAQ
Why limit remediation to two options?
Are mitigations not enough?
How many forms does the required action take?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).