< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 5 sources · 18 days · First seen · Last updated

Microsoft critical security vulnerability patches

Overview

Microsoft has released patches for several critical security vulnerabilities affecting its software ecosystem.

In July 2026, the company addressed a high-severity Active Directory Certificate Services (AD CS) flaw known as ‘Certighost’ (CVE-2026-54121). This vulnerability allowed regular domain users to impersonate a Domain Controller by exploiting a fallback mechanism, potentially leading to full Windows domain compromise.

By August 2026, Microsoft addressed additional critical flaws, including the ‘ShieldBreak’ zero-day and ‘LegacyHive’ (CVE-2026-62832). ShieldBreak targets Microsoft Defender, allowing local attackers to escalate privileges to the SYSTEM level via the cloud-hydration process. LegacyHive involves improper link resolution within the Windows User Profile Service, which could also grant local attackers administrator privileges.

Entities

Microsoft · Nightmare Eclipse · Windows Server 2025 · Aniq Fakhrul · Windows 11

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 29 days ago

    [TECHNOLOGY] 5 sources
    Microsoft patches Windows zero-day vulnerabilities

    Microsoft is patching multiple Windows vulnerabilities, including the ‘ShieldBreak’ zero-day in Defender, which allows local attackers to escalate privileges to SYSTEM level.

  2. about 2 months ago

    [TECHNOLOGY] 2 sources
    Microsoft patches critical Certighost (CVE‑2026‑54121) AD CS flaw

    Microsoft patched the Certighost (CVE‑2026‑54121) AD CS flaw that let ordinary users impersonate domain controllers and steal Kerberos tickets.

Sources

borncity.com · cybernoz.com · gr.pcmag.com · memesita.com · technews.bg