CVE-2026-54121
Published Jul 14, 2026
Last updated 2 months ago
AI description
CVE-2026-54121, also known as "Certighost," is an improper authorization vulnerability found in Microsoft Active Directory Certificate Services (AD CS). This flaw allows an authenticated attacker with low-privilege network access to elevate their privileges within an Active Directory environment. The vulnerability stems from insufficient permission checks during AD CS request handling, specifically within a vulnerable enrollment fallback mechanism known as a "chase" during directory-object resolution. By exploiting this weakness, an attacker can cause the Certification Authority (CA) to follow an attacker-controlled host for identity data, enabling them to impersonate a Domain Controller. This can lead to significant compromise of domain services, including the ability to obtain a certificate representing a privileged account and authenticate to services as that principal. Microsoft released a security update in July 2026 to address this issue.
- Description
- Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-285
- Hype score
- Not currently trending
📉 Certighost (CVE-2026-54121) business impact: Full CIA triad. Compliance exposure. Downtime. The line for your board: Patching does not revoke stolen secrets. A leaked krbtgt hash forges tickets until rotated twice. That's a recovery project. #CyberRisk #CISO https://t.c
@wepratik
30 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-54121 lets any domain user escalate to Domain Controller by exploiting Enterprise CA weaknesses. Audit PKI permissions and monitor certificate issuance closely to protect your Tier 0 assets. #CVE202654121 #PKISecurity #SOCMinute https://t.co/OlkmlQbkW8
@SOCMinute
18 Aug 2026
10 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Weekly detection rule digest covers 73 rule changes across 9 repos, with new Sigma coverage for ADCS CVE-2026-54121 (Certighost), AI agent threat rules, and email evasion detections topping the list. - SigmaHQ shipped 8 new rules for Certighost (CVE-2026-54121): watch Event ID h
@DFIR_Radar
10 Aug 2026
191 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
ドメインコントローラー証明書を不正取得しドメイン全体を侵害する認証バイパスの脆弱性「CVE-2026-54121(Certighost)」は、Microsoft Defender for Identityで検出可能 Detecting CVE-2026-54121 (Certighost) with Microsoft Defender https
@iejirok
2 Aug 2026
67 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CISO Daily Briefing: Arista VeloCloud Orchestrator zero-day (CVE-2026-16812, CVSS 10.0) is under active exploitation — CISA's KEV deadline is Thursday; also patch TeamCity's new unauthenticated RCE (CVE-2026-63077, CVSS 9.8) and the Certighost AD CS forgery bug (CVE-2026-54121)
@cloudsa
28 Jul 2026
440 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
1/3 A low privileged Active Directory user can impersonate a domain controller. A public exploit for CVE-2026-54121 dropped July 24, abusing Enterprise CA certificate issuance to seize the whole domain. Is your AD CS patched? #CyberSecurity #InfoSec #CVE https://t.co/F6cWIMiHyv
@CyberTLDR
25 Jul 2026
369 Impressions
0 Retweets
4 Likes
3 Bookmarks
1 Reply
0 Quotes
GitHub - tc4dy/CVE-2026-54121-PoC-Exploit: 👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework ⚡Weaponized tool with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. https://t.co/kDsO6JcT
@akaclandestine
25 Jul 2026
4960 Impressions
30 Retweets
97 Likes
70 Bookmarks
0 Replies
0 Quotes
A low-privileged user can steal a Domain Controller certificate using the Certighost flaw. Learn how CVE-2026-54121 works and why you need to patch now. For More: https://t.co/YgXZiLbCYF #Certighost #ActiveDirectory #ADCS #CVE #Cybersecurity #Kerberos #InfoSec #PatchTuesday htt
@redsecuretech
25 Jul 2026
63 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
‼️ PoC released for CVE-2026-54121 codenamed Certighost CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges. GitHub: https://t.co/puZfbilIlL https://t.co/9TzORX7x5z
@DarkWebInformer
24 Jul 2026
9463 Impressions
11 Retweets
40 Likes
24 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "1A8DB50E-7571-4925-A293-CAB93ECD0EBF",
"versionEndExcluding": "10.0.14393.9339",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "A9DC4EC9-4E72-4CBC-BA0B-39CCC45DB8CE",
"versionEndExcluding": "10.0.14393.9339",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "643F21D8-3A5B-477D-AFFC-2451DDC472CC",
"versionEndExcluding": "10.0.17763.9020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "A68E51D8-C76C-4C9E-9CBD-C7D4D4BCDFAA",
"versionEndExcluding": "10.0.17763.9020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "34D1270A-7D50-46CC-87EE-0A4E25F9C800",
"versionEndExcluding": "10.0.14393.9339",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D0E1AB94-0B38-4BB7-94EB-988EA266D6D5",
"versionEndExcluding": "10.0.17763.9020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9E9A0C18-3AD2-4E59-97AF-A2343E466929",
"versionEndExcluding": "10.0.20348.5386",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22BE2FE9-37B9-4FF2-B43A-60A3518E0F08",
"versionEndExcluding": "10.0.26100.33158",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]