Back to Feed
VulnerabilitiesJul 28, 2026

'Certighost' Flaw Haunts Microsoft Active Directory Certificates

Microsoft patched a high-severity flaw in Active Directory certificate services.

Summary

Microsoft has addressed a critical vulnerability, tracked as CVE-2024-26248, affecting its Active Directory Certificate Services (AD CS). This flaw allows an unauthenticated attacker to escalate privileges within an Active Directory environment, potentially leading to a full domain compromise. The vulnerability was patched in Microsoft's March 2024 security updates.

Indicators of Compromise

  • cve — CVE-2024-26248

Entities

Active Directory Certificate Services (product)Microsoft (vendor)Active Directory (technology)