Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

July 24, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations utilizing Microsoft Active Directory Certificate Services (AD CS)
Incident: Public disclosure of a proof-of-concept exploit for CVE-2026-54121.
Impact: Complete compromise of the Active Directory forest via Domain Controller impersonation and credential theft.
Attacker: Unidentified threat actors
Analysis: The Certighost exploit leverages a vulnerability in the AD CS ‘chase’ fallback mechanism, allowing attackers to relay authentication challenges via rogue SMB and LDAP listeners. By successfully impersonating a Domain Controller, a low-privileged user can obtain a certificate and execute a DCSync attack to extract the krbtgt secret. This chain effectively provides a path to total domain compromise without requiring administrator rights.
Recommendations: Immediately apply Microsoft’s July 14 updates to all AD CS hosts to patch CVE-2026-54121.; Disable the chase fallback using certutil if immediate patching is not feasible, though this may impact legitimate enrollment.; Monitor for unusual SMB and LDAP traffic originating from Certification Authorities toward non-DC assets.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *