logo

Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

ID: 06b41d09-b9fd-56b3-ad4f-de0ebfa235bb

STIX ID: report--06b41d09-b9fd-56b3-ad4f-de0ebfa235bb

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Guru Baran

...
...

A critical AD CS vulnerability dubbed Certighost (CVE-2026-54121) allowed low-privilege users to supply rogue chase targets during certificate enrollment so the CA issued certificates impersonating Domain Controllers; attackers could then authenticate as DCs and perform DCSync to obtain krbtgt and take over an Active Directory domain. Microsoft patched the flaw in July 2026 and recommends immediate patching and auditing or disabling the chase fallback (EDITF_ENABLECHASECLIENTDC) until updates are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.