Semperis disclosed two Active Directory privilege-escalation vulnerabilities involving hidden and unfilterable Unicode characters that can undermine Microsoft’s identity protections. The first flaw, KerberLoss (CVE-2026-25177), lets a low-privileged user with service principal name (SPN) write permissions bypass SPN and SPN-alias uniqueness checks, enabling denial of service against HOST-mapped services, SPN-jacking in constrained delegation scenarios, and forced Kerberos-to-NTLM downgrade. The second flaw, ResetNightmare (CVE-2026-27912), is more severe and allows an attacker who can write a user principal name (UPN) on a user or computer object to abuse NT-ENTERPRISE name handling and the Kerberos password-change protocol to reset a privileged account’s password and gain Domain Admin access.
The findings build on Microsoft’s earlier hardening work for CVE-2021-42282, which introduced uniqueness verification for UPNs, SPNs, and SPN aliases, but the new research shows those checks could still be bypassed under certain conditions. Microsoft patched KerberLoss in March 2026 and ResetNightmare in April 2026. Defenders were urged to update domain controllers, restrict delegated rights that allow SPN or UPN modification, and monitor Active Directory changes—particularly suspicious SPN and UPN edits such as Event ID 5136—for signs of exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft patched ResetNightmare, tracked as CVE-2026-27912. The vulnerability allowed a low-privileged attacker with UPN write access to reset a privileged account's password via Kerberos change-password abuse and ultimately obtain Domain Admin access.
Microsoft patched KerberLoss, tracked as CVE-2026-25177. The flaw allowed bypass of SPN and SPN-alias uniqueness checks using invisible unfilterable Unicode characters, enabling denial of service, SPN-jacking, and Kerberos-to-NTLM downgrade scenarios.
Microsoft's 2021 patch for CVE-2021-42282 added forest-wide uniqueness verification for user principal names, service principal names, and SPN aliases in Active Directory. This later became the baseline protection bypassed by the newly reported flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
semperis.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.