Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
ID: 06b41d09-b9fd-56b3-ad4f-de0ebfa235bb
STIX ID: report--06b41d09-b9fd-56b3-ad4f-de0ebfa235bb
Feed Name: cybersecurityNews.com
A critical AD CS vulnerability dubbed Certighost (CVE-2026-54121) allowed low-privilege users to supply rogue chase targets during certificate enrollment so the CA issued certificates impersonating Domain Controllers; attackers could then authenticate as DCs and perform DCSync to obtain krbtgt and take over an Active Directory domain. Microsoft patched the flaw in July 2026 and recommends immediate patching and auditing or disabling the chase fallback (EDITF_ENABLECHASECLIENTDC) until updates are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
