CVE-2026-54121

Published Jul 14, 2026

Last updated 2 months ago

CVSS high 8.8
Active Directory
Active Directory Certificate Services
AD CS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-54121, also known as "Certighost," is an improper authorization vulnerability found in Microsoft Active Directory Certificate Services (AD CS). This flaw allows an authenticated attacker with low-privilege network access to elevate their privileges within an Active Directory environment. The vulnerability stems from insufficient permission checks during AD CS request handling, specifically within a vulnerable enrollment fallback mechanism known as a "chase" during directory-object resolution. By exploiting this weakness, an attacker can cause the Certification Authority (CA) to follow an attacker-controlled host for identity data, enabling them to impersonate a Domain Controller. This can lead to significant compromise of domain services, including the ability to obtain a certificate representing a privileged account and authenticate to services as that principal. Microsoft released a security update in July 2026 to address this issue.

Description
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-285

Social media

Hype score
Not currently trending
  1. 📉 Certighost (CVE-2026-54121) business impact: Full CIA triad. Compliance exposure. Downtime. The line for your board: Patching does not revoke stolen secrets. A leaked krbtgt hash forges tickets until rotated twice. That's a recovery project. #CyberRisk #CISO https://t.c

    @wepratik

    30 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-54121 lets any domain user escalate to Domain Controller by exploiting Enterprise CA weaknesses. Audit PKI permissions and monitor certificate issuance closely to protect your Tier 0 assets. #CVE202654121 #PKISecurity #SOCMinute https://t.co/OlkmlQbkW8

    @SOCMinute

    18 Aug 2026

    10 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Weekly detection rule digest covers 73 rule changes across 9 repos, with new Sigma coverage for ADCS CVE-2026-54121 (Certighost), AI agent threat rules, and email evasion detections topping the list. - SigmaHQ shipped 8 new rules for Certighost (CVE-2026-54121): watch Event ID h

    @DFIR_Radar

    10 Aug 2026

    191 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. ドメインコントローラー証明書を不正取得しドメイン全体を侵害する認証バイパスの脆弱性「CVE-2026-54121(Certighost)」は、Microsoft Defender for Identityで検出可能 Detecting CVE-2026-54121 (Certighost) with Microsoft Defender https

    @iejirok

    2 Aug 2026

    67 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  5. CISO Daily Briefing: Arista VeloCloud Orchestrator zero-day (CVE-2026-16812, CVSS 10.0) is under active exploitation — CISA's KEV deadline is Thursday; also patch TeamCity's new unauthenticated RCE (CVE-2026-63077, CVSS 9.8) and the Certighost AD CS forgery bug (CVE-2026-54121)

    @cloudsa

    28 Jul 2026

    440 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 1/3 A low privileged Active Directory user can impersonate a domain controller. A public exploit for CVE-2026-54121 dropped July 24, abusing Enterprise CA certificate issuance to seize the whole domain. Is your AD CS patched? #CyberSecurity #InfoSec #CVE https://t.co/F6cWIMiHyv

    @CyberTLDR

    25 Jul 2026

    369 Impressions

    0 Retweets

    4 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  7. GitHub - tc4dy/CVE-2026-54121-PoC-Exploit: 👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework ⚡Weaponized tool with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. https://t.co/kDsO6JcT

    @akaclandestine

    25 Jul 2026

    4960 Impressions

    30 Retweets

    97 Likes

    70 Bookmarks

    0 Replies

    0 Quotes

  8. A low-privileged user can steal a Domain Controller certificate using the Certighost flaw. Learn how CVE-2026-54121 works and why you need to patch now. For More: https://t.co/YgXZiLbCYF #Certighost #ActiveDirectory #ADCS #CVE #Cybersecurity #Kerberos #InfoSec #PatchTuesday htt

    @redsecuretech

    25 Jul 2026

    63 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ‼️ PoC released for CVE-2026-54121 codenamed Certighost CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges. GitHub: https://t.co/puZfbilIlL https://t.co/9TzORX7x5z

    @DarkWebInformer

    24 Jul 2026

    9463 Impressions

    11 Retweets

    40 Likes

    24 Bookmarks

    1 Reply

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.