logo

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

ID: c8fe2a5b-5350-5463-8462-daeeebd2acc9

STIX ID: report--c8fe2a5b-5350-5463-8462-daeeebd2acc9

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Zeljka Zorz

...
...

CVE-2026-54121 ("Certighost") is a critical AD CS improper-authorization vulnerability (CVSS 8.8) that lets an authenticated domain user manipulate certificate enrollment attributes (cdc and rmd) to steer AD CS to a rogue host, obtain a CA-signed certificate for a targeted Domain Controller, use PKINIT to get Kerberos credentials for that DC, and then run DCSync to extract the krbtgt and achieve full domain compromise; Microsoft patched the flaw on July 14, 2026 and researchers published a PoC, with a registry-based mitigation available if patches cannot be applied immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.