Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, technique, sector-technology] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare] ยท au_impact: true

Certighost Exploit Lets Low-Privileged AD Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit for Cve 2026 54121 Certighost Adcs (dubbed Certighost, CVSS 8.8) allowing low-privileged Active Directory users to impersonate a Domain Controller and perform DCSync attacks.

Timeline

Date Event
~Mid July 2026 Microsoft patches the AD CS vulnerability in Patch Tuesday
2026-07-24 Researchers publish working exploit and analysis

Technical Summary

The exploit targets Microsoft's Active Directory Certificate Services (AD CS). A low-privileged user can: 1. Obtain a certificate for a Domain Controller machine account 2. Authenticate as that Domain Controller 3. Perform a DCSync attack to retrieve the krbtgt secret 4. Achieve full domain compromise

Impact

This is a critical privilege escalation chain for any organisation using AD CS. The exploit turns any authenticated domain user into a potential domain administrator, bypassing traditional security controls.

Australian Significance

AD CS is widely deployed across Australian government and enterprise environments. Organisations should prioritise verifying the July 2026 patches and auditing certificate templates.

Related Pages