CVE Tools

'Certighost' Flaw Haunts Microsoft Active Directory Certificates

Dark ReadingBy Elizabeth Montalbano

PoC publicActive Directory Certificate Services

Our summary

A proof-of-concept (PoC) exploit has been released for a critical vulnerability in Microsoft's Active Directory Certificate Services (AD CS), tracked as CVE-2026-54121. The flaw, dubbed 'Certighost,' enables a low-privileged domain user to impersonate a domain controller and fully compromise an Active Directory environment. Researchers demonstrated how attackers can manipulate certificate enrollment processes to trick the CA into trusting malicious hosts. Microsoft addressed the issue in its July Patch Tuesday updates. Organizations are urged to apply the patch immediately to prevent potential exploitation.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store