started · updated
Semperis researchers discover critical Active Directory vulnerabilities
Security researchers at Semperis have identified two critical Active Directory vulnerabilities, named ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), that could allow for full domain compromise.
Discovered by researcher Shai Laron, the flaws exploit hidden Unicode characters and weaknesses in name validation. This allows attackers to create accounts or services that appear to have identical names, causing identity confusion. Such exploitation can enable lateral movement, data theft, service disruption, or the deployment of ransomware. ResetNightmare is noted as particularly severe, as it could allow a low-privileged attacker to gain full control over an entire Active Directory domain.
Microsoft released patches for KerberLoss in March 2026 and ResetNightmare in April 2026. Organizations are advised to use Active Directory auditing, specifically Security Event ID 5136, to detect suspicious changes.
Entities
Australian Signals Directorate · Microsoft · Semperis · Shai Laron