The record
Written from the 3 reports below. Nothing here is unsourced.
- Researchers published a working exploit, called Certighost, for a vulnerability in Microsoft's Active Directory Certificate Services that lets a low-privileged domain user impersonate a Domain Controller and potentially steal the krbtgt secret via DCSync.
- Microsoft had patched the flaw, tracked as CVE-2026-54121 with a CVSS score of 8.8, ten days before the public disclosure on July 24.
- Exploitation needs only network access and a normal domain account, with no admin rights or user interaction, and works in forests with an Enterprise CA using the default Machine template.
- No exploitation in the wild had been reported as of July 24, but the full proof-of-concept is public, so organizations should apply the July 14 updates to AD CS hosts or use the lab-tested mitigation with caution.
What to watch next
- Signs of exploitation in the wild now that the proof-of-concept is public
- Whether the flaw is added to CISA's Known Exploited Vulnerabilities catalog
- Reports of the mitigation breaking legitimate certificate enrollment flows
What changed3
Every report on this story, newest first. Times are when each outlet published.
Coverage2
3 reports
English national2International1
All filed from India
Named United States · Active Directory Certificate Services · Aniq Fakhrul · bearskayankes · CISA · GitHub · H0j3n · Microsoft · n8n · Strix · Windows · Windows 10 · Windows Server 2012
- BleepingComputerNew Certighost PoC exploit lets attackers hijack Windows domains[1]International· neutral

- The Hacker NewsCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller[2]English national· neutral

- The Hacker Newsn8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer[3]English national· neutral

The 3 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.