A newly discovered Log4j vulnerability, CVE-2021-45046, reveals that the previous 2.15.0 patch remains incomplete and allows denial-of-service attacks. Experts recommend immediate upgrading or manually removing the JNDI Lookup class to mitigate the risk.