Certighost: A New AD CS Attack That Can Lead to Full Active Directory Compromise
Certighost: A New AD CS Attack That Can Lead to Full Active Directory Compromise
CertiGhost (CVE-2026-54121): AD CS Flaw Enables Domain Takeover | The CyberSec Guru
A newly disclosed AD CS vulnerability, CertiGhost (CVE-2026-54121), allows low-privileged domain users to impersonate a Domain Controller

A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) shows just how dangerous certificate-based authentication can become when trust breaks down. Certighost (CVE-2026-54121) allows a low-privileged domain user, under specific conditions, to obtain a certificate for a Domain Controller, authenticate using PKINIT, and perform DCSync to retrieve the krbtgt secret, potentially leading to complete Active Directory compromise. Microsoft patched the flaw in its July 2026 security updates, but a public proof-of-concept is now available