April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs

2026-04-15T07:23:51Z02adcf9a6c2f228b9d5b289863d5771920c5ce9b8824c94e1ca1dddc3c621858
ai-securityaxioscnappcritical-vulnerabilitiesdetectiondns-cname-abuseexposure-evaluationfalcon-data-securityfalcon-for-itkerberosnpmpatch-tuesdaysecure-bootstardust-chollimasupply-chainzero-day

What happened

CrowdStrike blog roundup (Apr 2026) highlighting April Patch Tuesday with 164 CVEs (including two zero‑days and eight critical flaws), detection guidance for a Kerberos authentication relay via DNS CNAME abuse, and a likely STARDUST CHOLLIMA compromise of the axios npm package. Additional posts cover secure‑boot certificate lifecycle management in Falcon for IT, Falcon Data Security, CNAPP enhancements with adversary‑informed risk prioritization, exposure evaluation improvements, and AI/agent security topics (Anthropic/Mythos, Charlotte AI).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
02adcf9a6c2f228b9d5b289863d5771920c5ce9b8824c94e1ca1dddc3c621858
Enrichment time
2026-04-15T07:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs · Baitaphish