CVE Tools

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Help Net SecurityBy Zeljka Zorz

PoC publicActive Directory Certificate ServicesWindows Server

Our summary

A proof-of-concept (PoC) exploit has been published for CVE-2026-54121, a high-severity privilege escalation vulnerability in Microsoft's Active Directory Certificate Services (AD CS). The flaw allows an authenticated attacker to forge certificates and impersonate domain controllers, potentially leading to full domain compromise. Researchers disclosed the issue in May 2026, and Microsoft issued patches on July 14, 2026. However, the release of the PoC raises concerns about potential real-world exploitation. Administrators are urged to apply updates or use mitigation strategies such as registry changes to disable the vulnerable fallback behavior.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store