CVE-2026-54121 is a critical vulnerability in Microsoft's Active Directory Certificate Services (AD CS) that allows low-privileged users to impersonate a Domain Controller. It was patched on July 14, 2026, and has a CVSS score of 8.8. Exploitation can lead to full domain compromise via DCSync attacks.