Back Feeds.4Sysops Certighost vulnerability allows domain controller impersonation via AD CS
The Certighost vulnerability, tracked as CVE-2026-54121, allows low-privileged users to impersonate a Domain Controller by exploiting a flaw in Active Directory Certificate Services (AD CS). By manipulating the enrollment protocol's chase mechanism, an attacker can force a Certificate Authority to issue a certificate for a target machine. This process requires the attacker to host rogue SMB and LDAP services to relay authentication challenges, effectively tricking the CA into validating a malicious request. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
