Public exploit for "Certighost" AD CS flaw lets any domain user impersonate a Windows domain controller
Security researchers published a working exploit for CVE-2026-54121, dubbed Certighost, a critical flaw in Microsoft $MSFT Active Directory Certificate Services. A regular domain account with no admin rights can obtain a certificate that impersonates a domain controller, opening
A public proof-of-concept exploit is now available for CVE-2026-54121 (Certighost), a critical CVSS 8.8 flaw in Active Directory Certificate Services. Researchers reported the bug to Microsoft $MSFT in May 2026; Microsoft $MSFT patched it on July 14, 2026 and published the technical details and exploit code on July 24. A regular, low-privilege domain account, with no admin rights and no user interaction, can trick a vulnerable Certificate Authority into issuing a certificate that authenticates as a domain controller, then use DCSync to extract the krbtgt secret and compromise the entire Windows domain. As of this week, no in-the-wild exploitation has been reported, but administrators who have not applied the July update should treat this as urgent.