Skip to content

New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations

Cybersecuritynews Abinaya January 19, 2026

A critical flaw in Windows Kerberos authentication that significantly expands the attack surface for credential relay attacks in Active Directory environments. By abusing how Windows clients handle DNS CNAME responses during Kerberos service ticket requests, attackers can coerce systems into requesting tickets for attacker-controlled services, bypassing traditional protections. The Attack Vector The vulnerability centers on […]

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)