CVE Tools

New Certighost PoC exploit lets attackers hijack Windows domains

BleepingComputerBy Lawrence Abrams

PoC publicWindows Active Directory Certificate Services

Our summary

A proof-of-concept exploit has been made public for a critical flaw in Microsoft's Active Directory Certificate Services, allowing attackers to take control of entire Windows domains. The vulnerability, identified as CVE-2026-54121, was addressed in the July 2026 Patch Tuesday updates but remains exploitable due to the newly released code. Researchers H0j3n and Aniq Fakhrul revealed how an authenticated user with minimal privileges could abuse a certificate enrollment mechanism to impersonate a domain controller and execute high-privilege actions. This poses a serious risk to unpatched systems, especially those still running outdated configurations.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store