Certighost (CVE-2026-54121) - AD CS Domain Controller Impersonation

Overview Certighost is an Active Directory Certificate Services vulnerability disclosed on July 24, 2026 by researchers H0j3n and aniqfakhrul. It allows a low-privileged domain user to impersonate a Domain Controller and achieve full domain compromise, including DCSync and krbtgt extraction. Patched in the July 2026 Patch Tuesday as CVE-2026-54121. If your Enterprise CA has not been updated, patch now. CVE: CVE-2026-54121 Researchers: H0j3n, aniqfakhrul Patched: July 14, 2026 Disclosed: July 24, 2026 Impact: Full domain compromise from low-privileged user Affected component: Active Directory Certificate Services - Enterprise CA Background AD CS is Microsoft’s PKI implementation. It issues X.509 certificates used for authentication. A client requests a certificate from an Enterprise CA, then presents it to the KDC via PKINIT to obtain a Kerberos TGT. ...

July 26, 2026 · 4 min · Tony Merisan