PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
PoC publicActive Directory Certificate ServicesWindows ServerOur summary
A proof-of-concept (PoC) exploit has been published for CVE-2026-54121, a high-severity privilege escalation vulnerability in Microsoft's Active Directory Certificate Services (AD CS). The flaw allows an authenticated attacker to forge certificates and impersonate domain controllers, potentially leading to full domain compromise. Researchers disclosed the issue in May 2026, and Microsoft issued patches on July 14, 2026. However, the release of the PoC raises concerns about potential real-world exploitation. Administrators are urged to apply updates or use mitigation strategies such as registry changes to disable the vulnerable fallback behavior.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.