New Certighost PoC exploit lets attackers hijack Windows domains
ID: d8b3d4dd-a5a5-5b01-9483-5420d51e3d67
STIX ID: report--d8b3d4dd-a5a5-5b01-9483-5420d51e3d67
Feed Name: Bleeping Computer
Threat Score
Certighost (CVE-2026-54121) is an AD CS vulnerability allowing an authenticated low-privileged user to abuse the AD CS "chase" fallback to obtain a certificate for a targeted Domain Controller, authenticate via PKINIT, extract Kerberos credentials and perform DCSync to retrieve sensitive account secrets; Microsoft patched the issue in July 2026 and researchers have published a proof-of-concept exploit (certighost.py), with a temporary mitigation available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
