April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs
2026-04-15T07:23:51Z•02adcf9a6c2f228b9d5b289863d5771920c5ce9b8824c94e1ca1dddc3c621858
ai-securityaxioscnappcritical-vulnerabilitiesdetectiondns-cname-abuseexposure-evaluationfalcon-data-securityfalcon-for-itkerberosnpmpatch-tuesdaysecure-bootstardust-chollimasupply-chainzero-day
What happened
CrowdStrike blog roundup (Apr 2026) highlighting April Patch Tuesday with 164 CVEs (including two zero‑days and eight critical flaws), detection guidance for a Kerberos authentication relay via DNS CNAME abuse, and a likely STARDUST CHOLLIMA compromise of the axios npm package. Additional posts cover secure‑boot certificate lifecycle management in Falcon for IT, Falcon Data Security, CNAPP enhancements with adversary‑informed risk prioritization, exposure evaluation improvements, and AI/agent security topics (Anthropic/Mythos, Charlotte AI).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- 02adcf9a6c2f228b9d5b289863d5771920c5ce9b8824c94e1ca1dddc3c621858
- Enrichment time
- 2026-04-15T07:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.