Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller. A working public exploit for CVE-2026-54121 allows any authenticated domain user to obtain a Domain Controller certificate and execute DCSync to retrieve the krbtgt secret, requiring no admin rights or user interaction. Defenders should treat this as a near-term lateral movement accelerator and prioritize patching ADCS environments immediately.
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available. CVE-2026-16723 enables unauthenticated remote code execution against Spring Boot applications using Alibaba's Fastjson 1.x library, and no patched version of the 1.x branch exists as of this writing. Organizations should enable SafeMode as an immediate workaround or accelerate migration to Fastjson2.
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers. Two patched CVEs (CVE-2026-32194 and CVE-2026-32191) in Bing's image-processing pipeline allowed attackers to execute arbitrary commands as SYSTEM on Windows and root on Linux workers via malicious SVG uploads, exploiting ImageMagick delegate functionality. Microsoft patched server-side prior to disclosure; this is a reminder that image-processing pipelines are a persistent blind spot in cloud attack surfaces.
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git. A public proof-of-concept enables any authenticated user on unpatched self-managed GitLab instances to execute commands as the git user by committing crafted Jupyter notebooks. The underlying Oj gem fix was quietly bundled into a non-security release, meaning many administrators may not have applied it.
Key Takeaway
Patch ADCS (CVE-2026-54121) and GitLab this week; if Fastjson 1.x is in your Java stack, enable SafeMode now and track the patch release daily.
