Certighost Vulnerability Enables Domain Controller Impersonation via AD CS

Certighost Vulnerability Enables Domain Controller Impersonation via AD CS

First seen 25 Jul 2026, 01:49 UTC CybersecuritynewsFeeds.4Sysops 82% similarity 70.5

Article Content

Browse articles
ThreatCluster

The Certighost vulnerability, tracked as CVE-2026-54121, allows low-privileged users to impersonate a Domain Controller by exploiting a flaw in Active Directory Certificate Services (AD CS). Attackers can manipulate the enrollment protocol's chase mechanism to trick a Certificate Authority into issuing a certificate for a target machine. This requires hosting rogue SMB and LDAP services to relay authentication challenges. The vulnerability affects organizations using AD CS, posing a significant risk of unauthorized domain control. Microsoft has released security updates to patch this flaw as of July 2026, following responsible disclosure earlier this year. The first public proof of concept (PoC) was made available on July 24, 2026, raising concerns about potential exploitation. Security professionals are urged to apply the patches promptly to mitigate risks.

Key Points: • CVE-2026-54121 allows low-privileged users to impersonate Domain Controllers. • Attackers exploit AD CS by manipulating the enrollment protocol's chase mechanism. • Microsoft released patches in July 2026 following responsible disclosure.

ThreatCluster AI

Timeline

2026-07-14
CVE-2026-54121 published
The vulnerability was officially tracked as CVE-2026-54121, detailing its impact on AD CS.
Feeds.4Sysops
2026-07-24
First public PoC released
A proof of concept demonstrating the Certighost vulnerability was made public, raising exploitation concerns.
Feeds.4Sysops
2026-07-24
Vulnerability disclosed in news articles
Cybersecurity news outlets reported on the Certighost vulnerability, emphasizing its severity and impact.
Cybersecuritynews
2026-07-25
Microsoft patches released
Microsoft issued security updates to address the Certighost vulnerability, urging immediate application by users.
Cybersecuritynews

Community

Browse all →