Certighost: new exploit lets low-privileged Windows users impersonate a domain controller
Researchers published a working exploit called Certighost for an Active Directory Certificate Services flaw (CVE-2026-54121) that lets a normal domain user account obtain a certificate impersonating a domain controller, enabling full domain compromise via DCSync. Microsoft patche
A newly disclosed Active Directory Certificate Services vulnerability called Certighost, tracked as CVE-2026-54121, let low-privileged Windows domain users obtain a certificate impersonating a Domain Controller and extract every password hash on the network via DCSync. Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24, 2026, ten days after Microsoft's July 14 patch. The flaw carries a CVSS score of 8.8. As of publication, no confirmed in-the-wild exploitation had been reported, but the full proof-of-concept is public on GitHub. Sources: The Hacker News, Cyber Security News.