Back to advisories

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate risk.

CRITICALAdvisoryJul 25, 2026
Action required
Patch all domain controllers and CA servers for CVE-2026-54121 immediately. Hunt for suspicious certificate requests from low-privileged accounts and monitor for DCSync activity via Directory Replication Service (DRS) protocols.
Affected products
Windows ServerMicrosoft