CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-54121: Active Directory Certificate Services Improper Authorization Vulnerability

July 24, 2026

CVE-2026-54121 is a critical vulnerability in Microsoft's Active Directory Certificate Services (AD CS) that allows low-privileged users to impersonate a Domain Controller. It was patched on July 14, 2026, and has a CVSS score of 8.8. Exploitation can lead to full domain compromise via DCSync attacks.