Skip to content
New Exploits Target PowerShell and Log4j Vulnerabilities

New Exploits Target PowerShell and Log4j Vulnerabilities

First seen 29 Sep 2026, 07:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 08:10 UTC
  • •Stracciatella exploit disables PowerShell security features for script execution.
  • •LogJackFix addresses the critical Log4j CVE-2021-44228 vulnerability.
  • •Both exploits were released in late September 2026, highlighting ongoing security threats.

Two new exploits have emerged, targeting PowerShell and the Log4j vulnerability CVE-2021-44228. The Stracciatella exploit allows execution of PowerShell scripts with disabled security features, potentially affecting systems using PowerShell in unprotected environments. Meanwhile, the LogJackFix exploit addresses the Log4j vulnerability, which has been exploited in the wild since its discovery. The Stracciatella exploit is designed for advanced adversarial simulations, while LogJackFix aims to protect Minecraft clients from remote code execution risks. Both tools highlight ongoing concerns regarding the security of widely used software frameworks. The Stracciatella exploit was published on September 29, 2026, while LogJackFix was released a day earlier on September 28, 2026. Security professionals are urged to assess their environments for these vulnerabilities and implement necessary mitigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-12-10
CVE-2021-44228 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
LogJackFix exploit released
A plugin for Spigot was released to fix the Log4j CVE-2021-44228 vulnerability affecting Minecraft clients.
Sploitus
2026-09-29
Stracciatella exploit released
The Stracciatella exploit was published, allowing PowerShell script execution with disabled security features.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2021-44228 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed