Back to Feed
VulnerabilitiesJul 28, 2026

'Certighost' Flaw Haunts Microsoft Active Directory Certificates

Microsoft patched a high-severity flaw in Active Directory certificate services.

Vendor Watch

Run Microsoft?

Get an email when a reviewed story names Microsoft, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Microsoft has addressed a critical vulnerability, tracked as CVE-2024-26248, affecting its Active Directory Certificate Services (AD CS). This flaw allows an unauthenticated attacker to escalate privileges within an Active Directory environment, potentially leading to a full domain compromise. The vulnerability was patched in Microsoft's March 2024 security updates.

Indicators of Compromise

  • cve — CVE-2024-26248

Entities

Active Directory Certificate Services (product)Microsoft (vendor)Active Directory (technology)