Microsoft released a security update for CVE-2026-69821, an important elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS). A locally authenticated attacker with low privileges could exploit the flaw to obtain SYSTEM privileges without user interaction, potentially gaining complete control of an affected Windows host.
The vulnerability is associated with CWE-116, improper encoding or escaping of output, and carries a CVSS v3.1 base score of 7.8. Microsoft reported that a fix is available and, at disclosure, had found no public disclosure or evidence of exploitation in the wild; it assessed exploitation as less likely.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-69821, an Important Active Directory Certificate Services elevation-of-privilege vulnerability caused by improper output encoding or escaping. A locally authenticated low-privileged attacker could obtain SYSTEM privileges without user interaction; Microsoft released an official fix and reported no public disclosure or in-the-wild exploitation at original publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.