logo

Detecting Certighost (CVE-2026-54121): Sigma Coverage Across the Full Attack Chain

ID: 430d2f84-41bd-57ee-bc55-1b4b1f7b6cc2

STIX ID: report--430d2f84-41bd-57ee-bc55-1b4b1f7b6cc2

Feed Name: Nextron Systems

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Swachchhanda Shrawan

...
...

Certighost (CVE-2026-54121) is a high-impact AD CS vulnerability where a CA configured with the EDITF_ENABLECHASECLIENTDC flag will follow an attacker-supplied 'cdc' address, accept a forged Domain Controller identity, and issue a DC certificate; an attacker can then obtain a DC TGT via PKINIT and perform DCSync to extract all domain credentials including krbtgt. The report reproduces the attack in-lab, provides detailed evidence (CA/DC/network logs), supplies seven Sigma detection rules and supporting checks, and recommends either disabling the chase flag or applying the July 2026 patch that validates chase targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.