On July 24, 2026, researchers H0j3n and Aniq Fakhrul published a working exploit for a Microsoft Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost. The flaw, assigned CVE-2026-54121, allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine. This enables the attacker to perform DCSync attacks and retrieve the krbtgt secret, compromising the entire domain.
Microsoft patched the issue on July 14, 2026, classifying it as improper authorization with a CVSS score of 8.8. Exploitation requires network access and a domain account but no administrator rights or user interaction. The attack chain involves an Enterprise CA with a vulnerable chase fallback, the default Machine certificate template, and network reachability from the CA to the attacker’s SMB and LDAP listeners.
The public exploit automates the process by creating or reusing a computer account, starting listeners on ports 445 and 389, relaying the CA’s authentication challenge to the real Domain Controller over Netlogon, and submitting crafted cdc and rmd attributes. The resulting certificate is used via PKINIT to authenticate as the target Domain Controller, allowing DCSync to extract secrets.
Microsoft’s July update adds validation in certpdef.dll to prevent the attack. As a temporary mitigation, administrators can disable the chase flag by running: certutil -setreg policyEditFlags -EDITF_ENABLECHASECLIENTDC and restarting Certificate Services. However, this may break legitimate enrollment flows, and the permanent fix is to apply the July 14 updates on AD CS hosts.
As of July 24, no exploitation in the wild has been confirmed, but the full proof-of-concept is public, increasing the risk of attacks.
CVEs: CVE-2026-54121
Companies: Microsoft
Products: Active Directory Certificate Services, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025, Windows 10
Original source: thehackernews.com