New Certighost PoC exploit lets attackers hijack Windows domains
PoC publicWindows Active Directory Certificate ServicesOur summary
A proof-of-concept exploit has been made public for a critical flaw in Microsoft's Active Directory Certificate Services, allowing attackers to take control of entire Windows domains. The vulnerability, identified as CVE-2026-54121, was addressed in the July 2026 Patch Tuesday updates but remains exploitable due to the newly released code. Researchers H0j3n and Aniq Fakhrul revealed how an authenticated user with minimal privileges could abuse a certificate enrollment mechanism to impersonate a domain controller and execute high-privilege actions. This poses a serious risk to unpatched systems, especially those still running outdated configurations.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.