Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft AD CS security update for CVE-2026-54121

Security Patch Release
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft's July 14 update patched CVE-2026-54121 in Active Directory Certificate Services (AD CS), closing an improper authorization flaw that could let a low-privileged domain user impersonate a Domain Controller. The release matters because the resulting credential path could reach DCSync and expose krbtgt. Administrators running an Enterprise CA were told to install the update on AD CS hosts.

Related Happenings

Microsoft YellowKey patch release (CVE-2026-45585)

Security Patch Release
H score20 First: 11.06.2026 20:43 Last: 11.06.2026 20:43 Sources 1

About this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...

Windows 10 KB5094127 extended security update

Security Patch Release
H score10 First: 09.06.2026 21:35 Last: 09.06.2026 21:35 Sources 1

About this happening: Microsoft released Windows 10 KB5094127 for Windows 10 Enterprise LTSC and ESU-enrolled devices, delivering the June 2026 Patch Tuesday security fixes and extendin...

CCB urgent patch warning for CVE-2026-41089 on Windows servers

Public Sector Action
H score48 First: 01.06.2026 15:30 Last: 01.06.2026 15:30 Sources 1

About this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...

Microsoft security patch release for CVE-2026-45659

Security Patch Release
H score23 First: 26.05.2026 14:49 Last: 26.05.2026 14:49 Sources 1

About this happening: Microsoft released SharePoint updates for CVE-2026-45659, a remote code execution flaw that could let an authenticated attacker run code over the network without eleva...

TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926

Security Patch Release
H score45 First: 22.05.2026 11:19 Last: 22.05.2026 11:19 Sources 1

About this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....

Timeline

  1. 24.07.2026 17:15 2 articles · 5h ago

    Microsoft patches CVE-2026-54121 in Active Directory Certificate Services

    Mitigation Patch Update

    Microsoft released the July 14 update for Active Directory Certificate Services that patched CVE-2026-54121, an improper-authorization flaw that could let a low-privileged Active Directory user obtain a certificate for a Domain Controller and use that credential path for DCSync.

    Show sources
  2. 24.07.2026 17:15 1 articles · 5h ago

    Researchers publish Certighost exploit for AD CS Domain Controller impersonation

    Initial Disclosure

    Researchers H0j3n and Aniq Fakhrul publicly disclosed Certighost on July 24 and published a working exploit for CVE-2026-54121 in Microsoft Active Directory Certificate Services, showing how a low-privileged Active Directory user can obtain a certificate for a Domain Controller and authenticate as that machine.

    Show sources