CVE-2026-54121
CVSS 8.8 HIGH: improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate… Microsoft patch: 5099538.
Patch available KB5099538 Download →
Vulnerabilities & Exploits
A normal domain user can abuse AD CS to become a Domain Controller in the directory. The broken step is the CA trusting a requester-supplied directory lookup before it has proved the target is really a DC, so a low-privilege account can end up with a machine certificate that carries replication rights.
Researchers published a working Certighost exploit for CVE-2026-54121 on July 24, after Microsoft patched the flaw on July 14. The chain works in default-style environments with an Enterprise CA and the standard machine-account quota, and it can lead to DCSync access to krbtgt and other replication secrets.
Patching the CA closes the flaw, but the real risk is the trust path inside AD CS: any system that issues privileged certificates from directory lookups can turn an ordinary domain account into a high-trust machine identity.
4 sources · Jul 28
CVSS 8.8 HIGH: improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate… Microsoft patch: 5099538.
Patch available KB5099538 Download →
Dark Reading
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
originalBleepingComputer
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for
originalHelp Net Security
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) - Help Net Security
Security researchers who discovered and reported CVE-2026-54121 (aka "Certighost") in AD CS have released a PoC exploit.
originalPart of the PlainSec briefing for 2026-07-25
Every edition of this story: AD CS Trust Check Hands Users Domain Controller Power