CVE-2026-54121

Published Jul 14, 2026

Last updated 6 days ago

CVSS high 8.8
Active Directory
Active Directory Certificate Services
AD CS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-54121, also known as "Certighost," is an improper authorization vulnerability found in Microsoft Active Directory Certificate Services (AD CS). This flaw allows an authenticated attacker with low-privilege network access to elevate their privileges within an Active Directory environment. The vulnerability stems from insufficient permission checks during AD CS request handling, specifically within a vulnerable enrollment fallback mechanism known as a "chase" during directory-object resolution. By exploiting this weakness, an attacker can cause the Certification Authority (CA) to follow an attacker-controlled host for identity data, enabling them to impersonate a Domain Controller. This can lead to significant compromise of domain services, including the ability to obtain a certificate representing a privileged account and authenticate to services as that principal. Microsoft released a security update in July 2026 to address this issue.

Description
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-285

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

Configurations

References

Sources include official advisories and independent security research.