Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
ID: a85fb1d5-2f38-532b-b48e-4ab860cc0dab
STIX ID: report--a85fb1d5-2f38-532b-b48e-4ab860cc0dab
Feed Name: HackRead
Threat Score
**Certighost (CVE-2026-54121)**: A high-severity AD CS vulnerability allowed attacker-controlled directory responses during the CA "chase" process to be accepted as proof of identity, enabling issuance of valid certificates impersonating Domain Controllers; a PoC demonstrated obtaining Kerberos credentials and performing DCSync leading to potential full domain compromise, Microsoft patched the issue on July 14, 2026 and published mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
