< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Microsoft patches critical Certighost (CVE‑2026‑54121) AD CS flaw

A high‑severity vulnerability in Active Directory Certificate Services (AD CS), identified as CVE‑2026‑54121 and dubbed “Certighost,” allowed a regular domain user to obtain a certificate that impersonated a Domain Controller. The flaw exploited a fallback mechanism in AD CS, enabling attackers to acquire a Domain Controller certificate, extract the krbtgt hash via DCSync, and forge Kerberos tickets, potentially compromising an entire Windows domain. Researchers H0j3n and Aniq Fakhrul disclosed the issue to Microsoft in May 2026; a functional exploit was published a week later. Microsoft released a patch on July 14, 2026, addressing the certificate‑validation weakness. Organizations that still run unpatched AD CS, especially those with legacy or unattended Enterprise Certificate Authorities, remain at risk until the update is applied.

The advisory underscores the importance of promptly applying the July 14 update and auditing AD CS deployments for misconfigurations that could allow the exploit to succeed.

Entities

Active Directory Certificate Services · Aniq Fakhrul · CVE‑2026‑54121 · H0j3n · Microsoft