Skip to content
Certighost vulnerability allows domain controller impersonation via AD CS

Certighost vulnerability allows domain controller impersonation via AD CS

Feeds.4Sysops IT News July 24, 2026

The Certighost vulnerability, tracked as CVE-2026-54121, allows low-privileged users to impersonate a Domain Controller by exploiting a flaw in Active Directory Certificate Services (AD CS). By manipulating the enrollment protocol's chase mechanism, an attacker can force a Certificate Authority to issue a certificate for a target machine. This process requires the attacker to host rogue SMB and LDAP services to relay authentication challenges, effectively tricking the CA into validating a malicious request. Source

Extracted Entities