// Microsoft 365HIGH
Active Directory Certificate Services (AD CS) vulnerability CVE-2026-54121 (CVSS 8.8) affecting Microsoft infrastructure now has a public exploit available as of July 24. The flaw in the enrollment chase mechanism allows low-privileged domain users to forge Domain Controller certificates and authenticate as DC without admin rights, enabling DCSync attacks to steal NTDS hash material. Microsoft patched the issue July 14; no in-the-wild exploitation confirmed yet but proof-of-concept is public.
- Certighost Exploit Lets Low-Privileged Active Directory Users Im(opens in a new tab)
- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, (opens in a new tab)
- CertiGhost (CVE-2026-54121): AD CS Flaw Enables Domain Takeover (opens in a new tab)
- Certighost haunts Microsoft Active Directory Certificate Service(opens in a new tab)
- 'Certighost' Flaw Haunts Microsoft Active Directory Certificates(opens in a new tab)
// Get alerts for Microsoft 365