logo

Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation

ID: a85fb1d5-2f38-532b-b48e-4ab860cc0dab

STIX ID: report--a85fb1d5-2f38-532b-b48e-4ab860cc0dab

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Waqas

...
...

**Certighost (CVE-2026-54121)**: A high-severity AD CS vulnerability allowed attacker-controlled directory responses during the CA "chase" process to be accepted as proof of identity, enabling issuance of valid certificates impersonating Domain Controllers; a PoC demonstrated obtaining Kerberos credentials and performing DCSync leading to potential full domain compromise, Microsoft patched the issue on July 14, 2026 and published mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.