A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) shows just how dangerous certificate-based authentication can become when trust breaks down. Certighost (CVE-2026-54121) allows a low-privileged domain user, under specific conditions, to obtain a certificate for a Domain Controller, authenticate using PKINIT, and perform DCSync to retrieve the krbtgt secret, potentially leading to complete Active Directory compromise. Microsoft patched the flaw in its July 2026 security updates, but a public proof-of-concept is now available
Certighost: A New AD CS Attack That Can Lead to Full Active Directory Compromise
Submitted 1 day ago by UnLocoPoco@lemmy.world to cybersecurity@infosec.pub
https://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/