VYPR
Vendor

Crowdstrike

Products
9
CVEs
7
Across products
12
Status
Private

Products

9

Recent CVEs

7
  • CVE-2026-40050CriApr 21, 2026
    risk 0.64cvss 9.8epss 0.01

    CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM…

  • CVE-2026-40058HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud…

  • CVE-2025-1146HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.00

    CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon…

  • CVE-2025-42706MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long…

  • CVE-2025-42701MedOct 8, 2025
    risk 0.36cvss 5.6epss 0.00

    A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all…

  • CVE-2026-76380MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password…

  • CVE-2022-2841LowAug 22, 2022
    risk 0.21cvss 2.7epss 0.05

    A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the…

VYPR — Vulnerability Intelligence