Microsoft Patches High-Severity 'Certighost' Flaw (CVE-2026-54121) in Active Directory Certificate Services

AI-generated NewsSnap summary based on source reporting.
Published: 2026-07-28
Category: technology
Source: Dark Reading

Microsoft has released a patch for a high-severity vulnerability, tracked as CVE-2026-54121 and dubbed 'Certighost,' affecting its Active Directory Certificate Services (AD CS). This flaw could allow a low-privileged domain user to escalate privileges and fully compromise an Active Directory environment by impersonating a domain controller. The vulnerability stems from a defective trust boundary in the certificate-based client authentication aspect of AD CS. Researchers have released a proof-of-concept exploit, underscoring the importance of applying the July Patch Tuesday update.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai