// Alert

Microsoft 365 threat report

Active Directory Certificate Services (AD CS) vulnerability CVE-2026-54121 (CVSS 8.8) affecting Microsoft infrastructure now has a public exploit available as of July 24. The flaw in the enrollment chase mechanism allows low-privileged domain users to forge Domain Controller certificates and authenticate as DC without admin rights, enabling DCSync attacks to steal NTDS hash material. Microsoft patched the issue July 14; no in-the-wild exploitation confirmed yet but proof-of-concept is public.

// Get alerts for Microsoft 365