A critical vulnerability (CVE-2026-54121, called "Certighost") in Windows Active Directory Certificate Services was publicly disclosed with exploit code just 10 days after Microsoft's patch. The flaw allows low-privileged domain users to impersonate Domain Controllers and compromise enterprise networks.
14 reports · 13 independentother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
New ADCS vuln + PoC dropped Only requires a low priv user and results in a DC cert Certighost (CVE-2026-54121) https:// gist.github.com/H0j3n/a5ef2609 b5f2944ac2390a191a534c26
🤖 Certighost Exploit: a low-privileged Active Directory user can impersonate a Domain Controller via a published exploit by H0j3n & Aniq Fakhrul. Low-priv → DC cert → DCSync → krbtgt secret = full domain takeover. 🔗 https:// thehackernews.com/2026/07/cert ighost-exploit-lets-low-privileged.html # Exploit # ActiveDirectory # CyberSec
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July 2026 security updates foll
🤖 Certighost Exploit: Low-privileged Active Directory users can impersonate a Domain Controller via AD CS certificate abuse. PoC published July 24 by H0j3n & Aniq Fakhrul. The forged DC cert enables DCSync to retrieve krbtgt secrets. 🔗 https:// thehackernews.com/2026/07/cert ighost-exploit-lets-low-privileged.html # Certighost # AD # CyberSec
⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at imme
🚨 Low-privileged Active Directory user → Full Domain Admin? A new AD CS vulnerability called Certighost (CVE-2026-54121) makes it possible. The attack abuses the certificate enrollment "chase" mechanism to obtain a Domain Controller certificate, authenticate via PKINIT, perform DCSync, and ultimately extract the krbtgt secret for complete Active Directory compromise. ✅ No admin privileges require
# Windows : if you haven't patched your MS Windows estate with July Patch Tuesday updates, now it's time to do it! # CertiGhost CVE-2026-54121 vulnerability allows an unprivileged user on your network to fully compromise the Active Directory and the Proof-of-Cocept (#POC) is out: 👇 https:// thehackernews.com/2026/07/cert ighost-exploit-lets-low-privileged.html
Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration. https:// gist.github.com/H0j3n/a5ef2609 b5f2944ac2390a191a534c26
CertiGhost (CVE-2026-54121) was published on 24 July by H0j3n and Aniq F. I expected a ten-minute PoC run in my Ludus lab and lost the weekend instead. A low-privileged domain user points the CA to an attacker host. The CA calls back over SMB and LDAP for principal details and trusts the response. Give it a DC's SID and DNS name, and it signs a DC certificate. Research https:// gist.github.com/H0j
Certighost proof-of-concept for CVE-2026-54121 published just 10 days after Microsoft's patch, letting standard domain users impersonate Domain Controllers via AD CS. https:// deafnews.it/en/article/certigh ost-ten-days-after-the-patch-the-exploit-is-public-and-the-domain-falls
Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller. # Certighost # CVE202654121 # ADCS # ActiveDirectory https:// securityonline.info/certighost -cve-2026-54121/?utm_source=mastodon&utm_medium=jetpack_social