{"record":"CrowdStrike evidence record","url":"https://nexalign.io/vendors/crowdstrike","vendor":{"slug":"crowdstrike","name":"CrowdStrike","domain":"crowdstrike.com","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-17T16:19:17.200Z","coverage":{"earliest":"2022-08-22T08:05:12.000Z","latest":"2026-07-17T10:47:13.858Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":42,"kindsOfSource":6,"attributedAdvisories":4,"knownExploited":0,"registerEntriesNotAttributable":3,"practitionerThreads":17,"independentItems":2,"vendorPublishedItems":1,"shareFromSourcesTheVendorDoesNotControl":0.69},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":6,"latest":"2026-04-21T16:48:24.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":4,"latest":"2026-04-21T17:16:53.610Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":15,"latest":"2024-09-13T20:17:18.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":2,"latest":"2026-07-03T10:18:53.290Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":2,"latest":"2026-02-06T10:25:44.000Z"},{"source":"The vendor's own documentation","operator":"Vendor website, indexed by nexalign","classification":"vendor-controlled","items":13,"latest":"2026-07-17T10:47:13.858Z"}],"advisories":{"shown":4,"total":4,"truncated":false,"items":[{"id":"CVE-2026-40050","description":"CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale.","severity":"critical","cvss":9.8,"knownExploited":false,"date":"2026-04-21T17:16:53.610Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-40050","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24164"]},{"id":"CVE-2025-42706","description":"A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files.","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2025-10-08T18:15:34.727Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-42706","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-33298"]},{"id":"CVE-2025-42701","description":"A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files.","severity":"medium","cvss":5.6,"knownExploited":false,"date":"2025-10-08T18:15:34.520Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-42701","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-33293"]},{"id":"CVE-2025-1146","description":"CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud.","severity":"high","cvss":8.1,"knownExploited":false,"date":"2025-02-12T18:27:35.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-2021"]}]},"practitionerThreads":{"shown":5,"total":17,"truncated":true,"items":[{"title":"CrowdStrike vs SentinelOne","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1qxe1ea/crowdstrike_vs_sentinelone/","date":"2026-02-06T10:25:44.000Z"},{"title":"AMA Interest Check - I Led IR on Nation-State Attacks at Mandiant, FireEye &amp; CrowdStrike","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1q3k69c/ama_interest_check_i_led_ir_on_nationstate/","date":"2026-01-04T07:55:11.000Z"},{"title":"CrowdStrike ex-employees: 'Quality control was not part of our process'","context":"Hacker News","url":"https://news.ycombinator.com/item?id=41534716","date":"2024-09-13T20:17:18.000Z"},{"title":"CrowdStrike accepting the PwnieAwards for \"most epic fail\" at defcon","context":"Hacker News","url":"https://news.ycombinator.com/item?id=41217037","date":"2024-08-11T15:52:00.000Z"},{"title":"Parody site ClownStrike refused to bow to CrowdStrike's bogus DMCA takedown","context":"Hacker News","url":"https://news.ycombinator.com/item?id=41173486","date":"2024-08-06T18:07:07.000Z"}]},"independentCoverage":{"shown":2,"total":2,"truncated":false,"items":[{"title":"CrowdStrike - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/CrowdStrike","date":null},{"title":"CrowdStrike Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/crowdstrike","date":null}]},"vendorPublished":{"shown":1,"total":1,"truncated":false,"items":[{"title":"The CrowdStrike Falcon® Platform","url":"https://www.crowdstrike.com/en-us/platform/","date":"2026-07-17T10:47:13.858Z"}]},"openQuestions":["A further 3 register entries mention CrowdStrike without naming a product of CrowdStrike as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}