TechNewsReel
Live

Microsoft Patches Certighost Flaw as PoC Exploit Goes Public

A high-severity AD CS vulnerability lets low-privileged users impersonate domain controllers and seize full network control.

TechNewsReel Newsroom · July 28, 2026

Microsoft patched a critical Active Directory Certificate Services vulnerability on July 14, 2026, but a public proof-of-concept exploit released July 24 has heightened urgency for organizations to update.

Tracked as CVE-2026-54121 with a CVSS score of 8.8, the flaw was discovered by security researchers H0j3n and Aniq Fakhrul, who reported it to Microsoft on May 14, 2026. Dubbed "Certighost," the vulnerability allows a low-privileged domain user to impersonate a Domain Controller and achieve full domain compromise.

How the Attack Works

The vulnerability resides in AD CS's enrollment fallback mechanism known as a "chase," where the Certification Authority performs a second directory lookup during certificate issuance. Attackers manipulate this process using the "cdc" (Client DC) and "rmd" (Remote Domain) attributes to trick the CA into querying an attacker-controlled host for identity data instead of a legitimate domain controller.

"A low-trust party hands a high-trust component a pointer, and the component follows it without asking whether the target is who the pointer claims," said Jason Soroko, senior fellow at Sectigo, describing the broken trust boundary.

Once the attacker obtains a certificate for the Domain Controller, they can execute a DCSync attack to retrieve the krbtgt account's credentials, granting effective control over the entire Active Directory environment—the highest privilege level in a Windows network.

Patch Timeline and Risk

Microsoft released the fix July 14, 2026, as part of its monthly Patch Tuesday updates. The public PoC release ten days later means unpatched systems face elevated exploitation risk. The researchers confirmed the vulnerability allowed domain compromise "in the tested AD CS configuration."

Active Directory Certificate Services is Microsoft's PKI implementation for issuing X.509 certificates for authentication and secure communications. The chase mechanism was designed for cross-domain controller enrollment scenarios where the CA needs additional directory information, but the implementation failed to verify the authenticity of requester-supplied targets.

What Organizations Should Do

Apply the July 2026 Patch Tuesday updates to all systems running AD CS immediately. Given the severity—full domain takeover from a low-privileged starting position—this vulnerability warrants urgent attention even for organizations with strong perimeter defenses.

The Certighost disclosure follows a pattern of AD CS vulnerabilities discovered in recent years, highlighting the critical role certificate services play in Windows domain security and the cascading risks when enrollment mechanisms contain trust boundary flaws.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.