CVE-2022-26923
Known exploited · CISA KEV
CVSS 8.8 HIGH: active Directory Domain Services Elevation of Privilege Vulnerability EPSS 84% (100th percentile).
CISA federal remediation date Sep 8 · date passed
Vulnerabilities · 126 days ago
Misconfigured AD CS turns certificate issuance into a privilege-escalation path, not just PKI plumbing. Attackers can mint certificate-based identity that impersonates privileged accounts and slips past password-centric monitoring, so the real control point is certificate issuance and its logs.
Unit 42 says template misconfigurations and shadow credential abuse are being used together, including CVE-2022-26923 as an anchor for this class of AD CS abuse. The report ties the behavior to active use in the wild and adds behavioral detections for event log correlation and Cortex XDR alerts instead of a vendor patch.
The risk is durable impersonation of high-value identities across anything that trusts the CA. Even after passwords change, certificate-backed access can persist until the issued identity trail is found and removed.
Known exploited · CISA KEV
CVSS 8.8 HIGH: active Directory Domain Services Elevation of Privilege Vulnerability EPSS 84% (100th percentile).
CISA federal remediation date Sep 8 · date passed
1 source covering this story
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders.
Part of the PlainSec briefing for 2026-05-12