Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft Active Directory Certificate Services (AD CS) CVE-2026-54121 now has a public working exploit, exposing low-privileged domain users to Domain Controller impersonation and DCSync risk.
Related Happenings
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/Mitigation
H score48
First: 14.01.2026 11:38
Last: 14.01.2026 11:38
Sources 1
About this happening:
Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/MitigationAbout this happening: Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Latest development: 10.02.2026 21:06
Microsoft released Windows 10 KB5075912 and continues rolling out replacement Secure Boot certificates to targeted Windows devices through monthly Windows updates, expanding delivery only after devices show sufficient successful update signals ahead of the June 2026 expiration.
Timeline
-
24.07.2026 17:15 1 articles · 5h ago
Researchers report AD CS flaw to Microsoft
Initial DisclosureResearchers H0j3n and Aniq Fakhrul reported the Microsoft Active Directory Certificate Services (AD CS) improper-authorization flaw to Microsoft after finding that a low-privileged Active Directory user could obtain a certificate for a Domain Controller and authenticate as that machine.
Show sources
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15
-
24.07.2026 17:15 1 articles · 5h ago
Microsoft confirms the AD CS flaw
Untyped PhaseMicrosoft confirmed the Active Directory Certificate Services (AD CS) flaw that later received CVE-2026-54121 after reviewing the researchers' disclosure.
Show sources
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15
-
24.07.2026 17:15 1 articles · 5h ago
Microsoft patches AD CS chase handling in July update
Mitigation Patch UpdateMicrosoft's July 14 updates for Active Directory Certificate Services fixed CVE-2026-54121 by adding CRequestInstance::_ValidateChaseTargetIsDC in certpdef.dll, which rejects invalid cdc targets and requires a matching Active Directory computer object with SERVER_TRUST_ACCOUNT (8192) before the CA follows a chase.
Show sources
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15
-
24.07.2026 17:15 2 articles · 5h ago
Researchers publish the Certighost Domain Controller impersonation exploit
Technical Analysis UpdateResearchers H0j3n and Aniq Fakhrul publicly released the working Certighost exploit, showing that a low-privileged Active Directory user can chain a rogue SMB and LDAP listener with a Netlogon relay to obtain a Domain Controller certificate, authenticate with PKINIT, and reach DCSync access to secrets such as krbtgt.
Show sources
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15