⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

AD CS Misconfiguration (ESC1) Exploited in Red Team Assessment

July 24, 2026

CISA's red team abused a misconfigured AD CS certificate template (ESC1) to escalate privileges, a technique similar to the Certighost exploit, emphasizing the need for proper certificate template hardening.