Researchers disclosed a working exploit and public proof-of-concept for Certighost (CVE-2026-54121), a flaw in Microsoft Active Directory Certificate Services that lets a low-privileged domain user obtain a certificate for a legitimate Domain Controller and authenticate as that machine. The issue stems from the AD CS certificate enrollment "chase" fallback, which trusted a requester-supplied directory target without properly verifying it was a real Domain Controller; by relaying the CA's authentication and standing up rogue SMB, LDAP, and LSA services, an attacker can have the CA sign a target DC's identity into a certificate.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Nextron Systems published a defensive writeup for Certighost that reproduced the attack chain in a lab, released a read-only exposure checker, and mapped seven Sigma detection rules to stages including machine account creation, malicious certificate requests, outbound certsrv.exe LDAP/SMB traffic, certificate issuance, and anomalous Kerberos activity. The guidance also documented logging prerequisites for Event IDs 4886 and 4887 and recommended either applying Microsoft's July patch or disabling EDITF_ENABLECHASECLIENTDC where possible.
Researchers H0j3n and Aniq Fakhrul publicly disclosed working exploit details for the AD CS flaw they named Certighost on 2026-07-24. The disclosure showed how a low-privileged Active Directory user could obtain a Domain Controller certificate and potentially perform DCSync to steal secrets such as krbtgt.
Microsoft fixed the Active Directory Certificate Services flaw CVE-2026-54121 on 2026-07-14, adding validation to ensure the certificate enrollment chase target is a legitimate Domain Controller. The issue was rated CVSS 8.8 and addressed as an improper authorization vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
nextron-systems.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcegist.github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.