A security researcher operating under the name Chaotic Eclipse has published a zero-day vulnerability targeting CrowdStrike Falcon, the widely deployed endpoint security platform. Dubbed FalconFlank, the flaw enables privilege escalation by exploiting the software's office malicious macros remediation feature, according to a disclosure posted to GitHub. The researcher noted that CrowdStrike may have already deployed detections for the vulnerability, suggesting testers will need to add the proof-of-concept to exclusions or obfuscate it to observe the exploit in action.

The proof-of-concept operates on fully patched Windows 11 25H2 systems and Windows Server 2025 machines running CrowdStrike Falcon, according to the researcher's technical documentation. The FalconFlank disclosure arrives just days after the same researcher released HardBreacher, a privilege escalation exploit affecting Kaspersky's endpoint security product for Windows version 14.0.0.504. That proof-of-concept, though functional, was described by its author as "duct tapped" and prone to execution failures requiring multiple attempts. When successful, HardBreacher creates a file at C:\Windows\System32\MY_SNAKE_IS_SOLID.dll with full permissions for the current user. The researcher explained that taking control over Kaspersky's UI process causes the security software to malfunction dramatically, allowing unauthorized file access decisions and destabilizing the entire operating system.

Last month, Chaotic Eclipse disclosed ShieldBreak, assigned CVE-2026-69414, a Microsoft Defender zero-day that grants attackers the ability to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. The vulnerability represents a bypass of an earlier patch for CVE-2026-50656, known as RoguePlanet, and Microsoft has not yet issued a fix. LevelBlue's analysis described ShieldBreak as combining Cloud Files, Object Manager namespace manipulation, direct Windows Defender API invocation, and a timing race condition in the remediation pathway. The exploit redirects Windows Defender's own cleaning engine to write an attacker-controlled DLL to C:\Windows\System32\phoneinfo.dll, then achieves SYSTEM-level execution through the built-in Windows Error Reporting task.

The researcher stated in an August 14, 2026 post that Microsoft continues to "ghost" them and refuses all communication, claiming the company is attempting to portray them as "some insane criminal." Chaotic Eclipse said Microsoft's restrictions prevent them from reporting bugs to affected vendors, adding "they don't even bother to check my case to figure out what's wrong." The researcher announced plans to begin publishing third-party vulnerabilities in the window before Microsoft's monthly Patch Tuesday releases, writing "I just want to live like a normal human being for once in my life, is that too much to ask for...?" The cascade of zero-day disclosures from a single researcher highlights a breakdown in coordinated vulnerability disclosure processes, placing the burden of emergency patching on multiple security vendors simultaneously. Organizations relying on endpoint protection platforms now face a strategic choice between trusting vendor detection updates or accepting operational disruption from rushed mitigation measures.