Microsoft Patches High-Severity 'Certighost' Flaw (CVE-2026-54121) in Active Directory Certificate Services
Microsoft has released a patch for a high-severity vulnerability, tracked as CVE-2026-54121 and dubbed 'Certighost,' affecting its Active Directory Certificate Services (AD CS). This flaw could allow a low-privileged domain user to escalate privileges and fully compromise an Active Directory environment by impersonating a domain controller. The vulnerability stems from a defective trust boundary in the certificate-based client authentication aspect of AD CS. Researchers have released a proof-of-concept exploit, underscoring the importance of applying the July Patch Tuesday update.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.