TrollEye Security

Cyber News

CrowdStrike Falcon Glitch Crashes Windows Systems Globally

A faulty update to CrowdStrike Falcon crashed Windows systems worldwide, disrupting airports, TV stations, hospitals, and companies across nearly every sector in one of the most widespread IT outages in

Details of the Story

As reported by Bleeping Computer a recent update to CrowdStrike Falcon has caused significant disruptions worldwide, crashing Windows systems and impacting organizations across various sectors, including airports, TV stations, and hospitals. This incident has resulted in massive outages, affecting entire companies and fleets of hundreds of thousands of computers.

The glitch, which affects both Windows workstations and servers, has led to widespread system failures. Users have reported being stuck in a boot loop or encountering the Blue Screen of Death (BSOD) after installing the latest update for the CrowdStrike Falcon Sensor. Notably, emergency services in the U.S. and Canada have also been impacted, further exacerbating the situation.

CrowdStrike acknowledged the issue and published a technical alert, explaining that its engineers identified a problematic content deployment and have since reverted those changes. The issue stems from a Channel File within the update, which can be individually addressed without removing the entire Falcon Sensor update.

CrowdStrike has provided a workaround for affected systems:

  1. Boot Windows into Safe Mode or the Windows Recovery Environment.
  2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.
  3. Locate and delete the file matching “C-00000291*.sys”.
  4. Boot the system normally.

George Kurtz, President and CEO of CrowdStrike, confirmed the issue is due to a defect in a single content update for Windows hosts. He emphasized that CrowdStrike is actively working with customers to resolve the issue and recommended using official channels for communication.

For cloud and virtual environments, CrowdStrike suggests two options:

  1. Roll back to a snapshot before 04:09 UTC.
  2. Follow a seven-step procedure to detach, modify, and reattach the operating system disk volume.

The impact of the faulty update has been severe:

  • Emergency Services: 911 services in parts of New York, Alaska, Arizona, and Canada experienced disruptions. In Illinois, telecommunicators resorted to using paper until systems were restored.
  • Healthcare: Hospitals in the Netherlands (Scheper, Slingeland, emergency posts in Hoogeveen and Stadskanaal) and Spain (Terrassa University Hospital, Catalan Oncology Institute) faced significant issues. In the U.S., Bellevue Hospital and NYU Langone Hospital were also affected.
  • Airports: Major disruptions occurred at airports worldwide, including Schiphol, Melbourne, Zurich, Berlin, Barcelona, Brisbane, Edinburgh, Amsterdam, and London. In the U.S., JFK and LaGuardia airports grounded flights due to the update’s impact.
  • Television Stations: Networks like Sky News and ABC experienced disruptions as computers crashed.

The response from affected users has been overwhelmingly negative, with many expressing frustration over the widespread system failures. Reports from Reddit highlight the scale of the issue, with tens and hundreds of thousands of computers crashing across the globe.

Despite CrowdStrike’s efforts to deploy a fix and provide a workaround, the effects of this issue will likely be felt for some time. IT administrators face a challenging weekend ahead, especially in environments with large fleets of computers, remote workers, and cloud-based systems.

The recent CrowdStrike Falcon update glitch has underscored the critical importance of thorough testing and rapid response in cybersecurity. While CrowdStrike is working diligently to address the issue, the incident serves as a stark reminder of the potential consequences of software updates on global operations. Organizations must remain vigilant and prepared to respond to such incidents to ensure the stability and security of their systems.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated