Exploited Known exploited (KEV) Ransomware use CVE-2021-44228

Only two remediations count — CISA narrows the options on the Log4j2 flaw

Apache Log4j2 Added to KEV Dec 10, 2021 Federal remediation due 2021-12-24

For the remote code execution flaw in Apache Log4j2, CISA recognized nothing as remediation except applying updates or removing the affected assets from agency networks. Temporary mitigations were allowed only until updates existed.

Key facts

  • CVE IDCVE-2021-44228
  • Affected (vendor / product)Apache Log4j2
  • CWECWE-20, CWE-400, CWE-502
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2021-12-24 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2021-44228 is a remote code execution flaw in Apache Log4j2, arising where the JNDI functionality fails to guard against endpoints an attacker controls.
  • It entered the catalog on 10 December 2021 with remediation due 24 December 2021, and ransomware use is recorded as known.
  • The required action allows two remediations and no others: putting the update on, or taking the asset off agency networks.
  • Temporary mitigations from emergency directive ED 22-02 are acceptable only until updates become available.
  • Among the 1,579 entries without an article within the 1,695 records this site holds as of 2026-09-05, the required action takes forty forms and 889 (56.3%) share one line.

1The instructions have shapes too

The catalog of known exploited vulnerabilities is not merely a list of flaws. Each entry carries a field for the required action, setting out what federal agencies are to do. Most end in one line: apply updates per vendor instructions. This series takes up eight cases where that line was not enough.

2More than half end in that one line

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579The required action takes forty distinct forms
Of those, entries ending in the single line to apply updates per vendor instructions88956.3%
Entries carrying one of the remaining twenty-two forms27 in totalIndividually written instructions used one to four times each

The wording of the required action comes in forty forms only. A majority, 889 entries, share the same line. Against that, twenty-two of the forms appear on between one and four entries, and each of those carries something particular to the flaw it addresses.

3Two, and nothing else

The instruction on this entry closes off the alternatives explicitly.

The aspectA typical entryThis entry, Log4j2
How remediation is putApply updates per vendor instructionsOnly two remediation actions are acceptable
What countsApplying the updateApplying the update, or removing the asset from agency networks
MitigationsNot mentionedMeasures from emergency directive ED 22-02 hold only until updates exist
What followsContinuing to run a mitigated system is not remediation

The word acceptable is doing the work here. Whatever else an agency might devise does not count as remediation. Getting by on a mitigation is an exception permitted only while no update exists.

4Why spell it out

The entry was added on 10 December 2021 with a due date of 24 December: fourteen days. Log4j2 sits inside a great many other pieces of software as a component, so an organization often cannot establish its own exposure by itself. Ransomware use is recorded as known.

In that situation, leaving room for each agency to decide on its own that it has dealt with the problem is itself the danger. Limiting the answer to two is a way of closing that room. The next article takes up an entry that went further and set an order: cut the traffic before you fix anything.

Why it matters

The catalog of known exploited vulnerabilities is a body of instructions as much as a list of flaws. A majority need only the line about applying updates, but where an organization cannot establish its own exposure, the room each agency has to decide for itself that the matter is handled becomes the hazard. Narrowing acceptable remediation to two reads as a design for closing that room.

FAQ

Why limit remediation to two options?
The catalog gives no reason, but this flaw is recorded as known in ransomware use and was given a due date only fourteen days out.
Are mitigations not enough?
Measures from emergency directive ED 22-02 are stated to be acceptable only as temporary steps until updates become available.
How many forms does the required action take?
Across the 1,579 entries without an article this site holds as of 2026-09-05 there are forty, of which 889 (56.3%) are the single line to apply updates.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.