Application Security

Patch Windows Get Their Own Runtime Guard

The gap is the time between CVE disclosure and patch rollout. Contrast’s new CVE Shield is built to cover that window by blocking exploit behavior inside the app instead of waiting for every Java system to be fixed first.

It runs as a runtime microsandbox for supported CVEs, starting with 60 Java flaws including Log4Shell, Spring4Shell, and Apache Commons Collections. Contrast says it watches for the exploit’s needed capabilities, like native code execution, remote class loading, and arbitrary file writes, so new variants still hit the same block without a new signature.

The practical shift is that teams can keep vulnerable code live for a short period without leaving it fully open. That makes patch latency a managed exposure, not just a scheduling problem, especially as AI tools can generate working exploits faster than normal release windows.

1 source · Jul 29

CVE-2021-44228

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Dec 24 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-07-30

Every edition of this story: Patch Windows Get Their Own Runtime Guard