Kudelski Security Research Center
ID: 0b21d698-7885-5348-b786-bd29c2fa245e
STIX ID: report--0b21d698-7885-5348-b786-bd29c2fa245e
Feed Name: Kudelski Security
Certighost (CVE-2026-54121) is a critical AD CS vulnerability that lets a low‑privileged domain user manipulate the chase fallback process to obtain certificates impersonating a Domain Controller, enabling full domain compromise (e.g., DCSync). Microsoft released a July 2026 security update to validate chase targets; mitigations include applying the patch, disabling chase fallback, and restricting certificate template permissions. A public PoC exists and the issue should be treated as actively exploited.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
