Skip to content
Certighost Vulnerability Enables Domain Controller Impersonation via AD CS

Certighost Vulnerability Enables Domain Controller Impersonation via AD CS

First seen 25 Jul 2026, 01:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 26, 2026 at 00:04 UTC
  • CVE-2026-54121 allows low-privileged users to impersonate Domain Controllers.
  • Attackers exploit AD CS by manipulating the enrollment protocol's chase mechanism.
  • Microsoft released patches in July 2026 following responsible disclosure.

The Certighost vulnerability, tracked as CVE-2026-54121, allows low-privileged users to impersonate a Domain Controller by exploiting a flaw in Active Directory Certificate Services (AD CS). Attackers can manipulate the enrollment protocol's chase mechanism to trick a Certificate Authority into issuing a certificate for a target machine. This requires hosting rogue SMB and LDAP services to relay authentication challenges. The vulnerability affects organizations using AD CS, posing a significant risk of unauthorized domain control. Microsoft has released security updates to patch this flaw as of July 2026, following responsible disclosure earlier this year. The first public proof of concept (PoC) was made available on July 24, 2026, raising concerns about potential exploitation. Security professionals are urged to apply the patches promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-07-14
CVE-2026-54121 published
The vulnerability was officially tracked as CVE-2026-54121, detailing its impact on AD CS.
Feeds.4Sysops
2026-07-24
First public PoC released
A proof of concept demonstrating the Certighost vulnerability was made public, raising exploitation concerns.
Feeds.4Sysops
2026-07-24
Vulnerability disclosed in news articles
Cybersecurity news outlets reported on the Certighost vulnerability, emphasizing its severity and impact.
Cybersecuritynews
2026-07-25
Microsoft patches released
Microsoft issued security updates to address the Certighost vulnerability, urging immediate application by users.
Cybersecuritynews

More articles in this cluster (21)

Following this threat?

Track CVE-2026-54121 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed