Public exploitation evidence

CVE-2021-44228

As of 2026-09-12, CVE-2021-44228 has substantial public exploitation evidence: listed in CISA KEV, listed in ENISA EUVD (exploited), a public exploit module and a published exploit. Most recent observation: 2026-04-03.

Published to NVD: 2021-12-10.

Observation timeline

Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.

ObservationSourceDate
Listed in CISA KEV CISA KEV 2021-12-10 View →
Listed in ENISA EUVD (exploited) ENISA EUVD (Exploited) 2021-12-10 View →
Public exploit reference ExploitDB 2026-04-03 View →
Public exploit module Metasploit 2026-04-03 View →

Exposure class & technique

This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:

T1190 · Exploit Public-Facing Application

Weakness (CWE)

The MITRE CWE weakness types classified for this exposure class:

CWE-20 · Improper Input Validation CWE-400 · Uncontrolled Resource Consumption CWE-502 · Deserialization of Untrusted Data CWE-917 · Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

CISA KEV context

Remediation due date2021-12-24
Required actionFor all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
Known ransomware campaign use Yes
Commercial assessment

ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.

Get the assessment →

Public evidence is not the whole picture. Limited or absent observed evidence is not the same as safety.

Related CVEs

Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.

Look it up yourself

Get a free key and look up any CVE yourself.

New to this? See what an exposure signal is and how ESIP builds one.

Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-09-12