Active Directory Certificate Services (AD CS) has long been a favorite target for attackers.
The recently disclosed CertiGhost (CVE-2026-54121 – our CVE of the Week) vulnerability demonstrates that even well-managed environments can still contain unexpected paths to full domain compromise.
Microsoft addressed the issue in its July 2026 security updates, but the public release of a working Proof-of-Concept (PoC) has significantly increased the risk for unpatched organizations.
What makes CertiGhost particularly noteworthy is that it does not require administrative privileges. Under specific conditions, a standard authenticated domain user can obtain a certificate that allows them to authenticate as a Domain Controller, potentially leading to complete Active Directory compromise.
The vulnerability affects a little-known AD CS enrollment fallback mechanism known as a“chase”. During certificate issuance, the Certification Authority (CA) may query additional directory information using attributes such as cdc (Client DC) and rmd (Remote Domain). Researchers discovered that vulnerable implementations failed to properly verify whether the supplied domain controller target was actually legitimate. This creates an opportunity for attackers to redirect the CA toward attacker-controlled services.
By manipulating the certificate enrollment process and returning crafted identity information associated with a Domain Controller, attackers can trick the CA into issuing a certificate containing trusted DC identity attributes. Once a Domain Controller certificate is obtained, the impact becomes severe. The attacker can authenticate using PKINIT as that Domain Controller and leverage replication privileges to perform DCSync operations. This may expose sensitive secrets such as the krbtgt account, enabling Golden Ticket level access and effectively resulting in a complete domain takeover.
This is especially important because the attack chain can begin with nothing more than a low-privileged user account. Organizations relying on AD CS should immediately verify that security updates have been deployed to Enterprise CA servers. Microsoft has also warned that the publication of the PoC increases the likelihood of exploitation attempts in the wild.
Defenders should focus on:
Unusual AD CS certificate enrollment activity
DCSync-related alerts and directory replication abuse
AD CS remains one of the most critical yet often under-monitored components in many Windows environments. While much attention has historically focused on misconfigurations Certighost shows that implementation-level vulnerabilities can be just as dangerous. Now is a good time to review AD CS exposure, validate patch status, and ensure detection coverage includes certificate abuse scenarios.
In this week’s CVE of the Week, we’re examining a recently patched vulnerability chain in the Adobe Acrobat PDF Chrome extension, which is used by more than 314 million users worldwide. Tracked as CVE-2026-48294 (CVSS score: 8.2) and dubbed HermeticReader [...]
This week’s CVE of the Week is CVE-2026-24301, also known as CoSnitch, an exfiltration method in Microsoft Copilot that could allow an unauthorized attacker to steal sensitive information and data. With a CVSS score of 8.8, deserves serious attention. It is a combination of three different vulnerabilities that could allow an attacker to pull data ...
AI has been a hotspot for everything recently and that’s true for attacks too proven by the recently discovered and also exploited IBM Langflow OSS (versions 1.0.0 through 1.10.0) vulnerability CVE-2026-9198, our #CVEoftheWeek. The issue was addressed in the release of version 1.10.1 on 24th June, which contained many security updates, but known Proof-of-Concepts (PoC) ...
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.