A security researcher known as Chaotic Eclipse has released a proof-of-concept zero-day exploit called **FalconFlank**, which escalates privileges on fully patched Windows machines using CrowdStrike Falcon. This zero-day was published on GitHub on September 3, 2026, without prior notice to CrowdStrike. The exploit takes advantage of Falcon's macro removal feature, which operates with high privileges, to allow low-privileged accounts to gain SYSTEM rights. No CVE ID or CVSS score has yet been assigned, and CrowdStrike has not confirmed this vulnerability.
CrowdStrike Falcon Zero Day Gives Attackers SYSTEM Rights on Windows
CyberSIXT Evidence Panel
Primary Source
github.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline