Any employee's login can now become domain admin — and the exploit code is already public

A low-privileged Active Directory account is all it takes to forge a Domain Controller certificate — Microsoft patched it in July, and a working…

Aliteq
Priya Nair · Software & Systems Editor

Key point

CVE-2026-54121 ("Certighost") is a critical, CVSS 8.8 flaw in Active Directory Certificate Services affecting Windows 10 and Windows Server.

Key point

Any authenticated domain user — no administrator privileges required — can exploit it to forge a certificate and impersonate a Domain Controller.

Key point

Microsoft patched the flaw as part of the July 14, 2026 Patch Tuesday release, roughly two months after researchers privately reported it on May 14.

Key point

A public proof-of-concept tool, certighost.py, went live on GitHub on July 24, meaning any attacker can now weaponize this without doing their own research.

Key point

There are no confirmed reports of exploitation in the wild yet, but Microsoft's original 'exploitation less likely' rating is effectively obsolete now that working exploit code is public.

'No known exploitation' is a snapshot, not a guarantee

I'd treat 'no confirmed in-the-wild exploitation' as true only as of the article that reported it. A working Python exploit sitting on GitHub with a catchy name is exactly the profile of bug that…

Aliteq

Read the full story

Any employee's login can now become domain admin — and the exploit code is already public

Read the full story on Aliteq