A proof-of-concept exploit for the Certighost vulnerability (CVE-2026-54121) in Windows Active Directory Certificate Services allows authenticated attackers to impersonate domain controllers and gain domain-level privileges. The flaw exploited a fallback mechanism in certificate enrollment requests, permitting attackers to obtain unauthorized certificates and perform privileged Active Directory operations, including DCSync attacks. Microsoft addressed the issue in the July 2026 Patch Tuesday updates by validating domain controller identities during certificate requests, and administrators are urged to apply these patches promptly.
New Certighost PoC Exploit Lets Attackers Hijack Windows Domains

