Threat reportVulnerabilityTL-2026-1675

CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation

criticalPATCHED

CVE-2026-54121 ("Certighost") (TL-2026-1675), also tracked as Certighost, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-07-24 and last reviewed 2026-10-01. It has no confirmed attribution, affects Microsoft Windows Server (Active Directory Certificate Services role), references 1 CVE (CVE-2026-54121), maps to 28 MITRE ATT&CK techniques (T1003.006, T1018, T1036), and is covered by 9 detection rules and 43 indicators of compromise.

CVSS
8.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
28MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
43Indicators of compromise

Key facts for TL-2026-1675

Threat ID
TL-2026-1675
Also known as
Certighost
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, manufacturing, education, critical-infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
43
Updates
2026-10-01 · 4 updates · revalidated 4× · latest source

Malware and tooling in CVE-2026-54121 ("Certighost")

Malware and tooling: Certighost, Certipy

How CVE-2026-54121 ("Certighost") works

CVE-2026-54121 ("Certighost") is a CVSS 8.8 improper-authorization flaw in Active Directory Certificate Services (AD CS) that lets any authenticated low-privileged domain user relay a Certification Authority's "chase" fallback resolution to impersonate a Domain Controller, obtain a DC-identity certificate, authenticate via PKINIT, and perform DCSync against krbtgt. Microsoft patched it July 14, 2026 (Patch Tuesday); a working public PoC ("certighost.py") was released July 24, 2026 by researchers H0j3n and Aniq Fakhrul.

AD CS Enterprise Certification Authorities support a certificate-enrollment fallback path called a "chase": when the CA cannot directly resolve the identity of the end entity requesting a certificate, the enrollment protocol allows the requester to supply a `cdc` parameter (an Active Directory server/contact point) and an `rmd` parameter (the machine object to resolve) so the CA can go fetch the missing identity attributes itself. Prior to the July 2026 patch, the CA followed the requester-supplied `cdc` host over SMB and LDAP without first proving that host was a genuine Domain Controller.

An attacker holding nothing more than a standard domain account (or a computer account created under the default `ms-DS-MachineAccountQuota` of 10) can stand up rogue SMB (445) and LDAP (389) listener services, submit a certificate enrollment request whose `cdc` attribute points at the attacker's own host and whose `rmd` attribute names the real target Domain Controller, and let the CA's outbound Netlogon authentication challenge be relayed back to the legitimate DC. The rogue listeners respond with the target DC's `objectSid`, `sAMAccountName`, and `dNSHostName`, which the CA then binds into the issued certificate — producing a valid certificate that asserts the *attacker* is the Domain Controller.

That certificate is used to perform PKINIT Kerberos pre-authentication, yielding a TGT (and derivable NT hash / `.ccache`) for the DC's own machine account. Domain Controller machine accounts hold directory-replication rights (`Replicating Directory Changes` / `Replicating Directory Changes All`), so the attacker can immediately run DCSync to extract the `krbtgt` secret and every domain account credential — full domain compromise from a single unprivileged starting foothold, no admin rights and no user interaction required at any step.

Microsoft's July 14, 2026 update closes the gap by adding `CRequestInstance::_ValidateChaseTargetIsDC` to `certpdef.dll`, which rejects IP literals and over-long names, blocks LDAP metacharacters, requires exactly one matching AD computer object, validates DNS-name correspondence, confirms `userAccountControl` contains `SERVER_TRUST_ACCOUNT` (0x2000), and performs a SID comparison before honoring a chase target as a genuine DC.

A fully automated public exploitation tool (`certighost.py`, github.com/aniqfakhrul/CVE-2026-54121) was released July 24, 2026, ten days after the patch, that creates/reuses a rogue computer account, spins up the SMB/LDAP listeners, drives the enrollment/relay flow end-to-end, and drops a `.pfx` certificate plus a `.ccache` ready for immediate Kerberos-based domain impersonation. No confirmed in-the-wild exploitation had been reported as of the July 24, 2026 disclosure, but the combination of a trivial privilege bar (any domain account), zero user interaction, network-only attack vector, and a fully weaponized public PoC makes unpatched AD CS environments an urgent detection and patching priority.

MITRE ATT&CK techniques used in TL-2026-1675

Credential Access

T1003.006 OS Credential Dumping: DCSync; T1187 Forced Authentication; T1212 Exploitation for Credential Access; T1552 Unsecured Credentials; T1557.001 Name Resolution Poisoning and SMB Relay; T1558 Steal or Forge Kerberos Tickets; T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket

Discovery

T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account

Defense Evasion

T1036 Masquerading

Execution

T1059.006 Command and Scripting Interpreter: Python

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1098 Account Manipulation

Initial Access

T1078.002 Valid Accounts: Domain Accounts

Persistence

T1136.002 Create Account: Domain Account

defense-impairment

T1207 Rogue Domain Controller

Lateral Movement

T1210 Exploitation of Remote Services; T1550.003 Use Alternate Authentication Material: Pass the Ticket

Impact

T1531 Account Access Removal

Resource Development

T1587.001 Develop Capabilities: Malware; T1587.004 Develop Capabilities: Exploits; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1590.001 Gather Victim Network Information: Domain Properties; T1592.002 Gather Victim Host Information: Software; T1595.002 Active Scanning: Vulnerability Scanning

credential-access

T1649 Steal or Forge Authentication Certificates

Affected products and versions in CVE-2026-54121 ("Certighost")

  • Microsoft — Windows Server (Active Directory Certificate Services role)
    Vulnerable versions: Windows Server 2025 (pre-26100.33158); Windows Server 2022 (pre-20348.5386); Windows Server 2019 (pre-17763.9020); Windows Server 2016 (pre-14393.9339); Windows Server 2012 R2 (pre-6.3.9600.23291); Windows Server 2012; Windows 10 version 1607; Windows 10 version 1809
    Fixed in: Windows Server 2025 with KB5099536; Windows Server 2022 with KB5099540; Windows Server 2019 with KB5099538; Windows Server 2016 with KB5099535; Windows Server 2012 R2 with July 2026 ESU

Remediation for CVE-2026-54121 ("Certighost")

Patches

  • Windows Server 2025 — KB5099536 (build 26100.33158+)
  • Windows Server 2022 — KB5099540 (build 20348.5386+)
  • Windows Server 2019 — KB5099538 (build 17763.9020+)
  • Windows Server 2016 — KB5099535 (build 14393.9339+)
  • Windows Server 2012 R2 — July 2026 Extended Security Updates (build 6.3.9600.23291+)

Immediate actions

  • Install Microsoft's July 14, 2026 security updates on every host running the AD CS Certification Authority role (KB5099536 / KB5099540 / KB5099538 / KB5099535 or the July 2026 ESU for Server 2012 R2, as applicable to the OS version).
  • Inventory all Enterprise CAs and confirm the patched `certpdef.dll` build (containing `CRequestInstance::_ValidateChaseTargetIsDC`) is installed and `CertSvc` has been restarted to load it.
  • Audit and reduce `ms-DS-MachineAccountQuota` from the default value of 10 to 0 where computer self-provisioning by standard users is not required.
  • Monitor for anomalous new computer-account creation events (Event ID 4741) and unexpected inbound SMB (445) / LDAP (389) service bindings from non-DC domain-joined hosts.

Workarounds

  • Lab-tested-only temporary mitigation: `certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC` followed by `Restart-Service CertSvc -Force` to disable chase-client-DC resolution entirely. Researchers explicitly warn this can break legitimate enrollment flows and should be staged/tested before production use, and treated only as a bridge to the official patch, never a permanent fix.

Longer-term hardening

  • Deploy AD CS enrollment auditing and certificate-issuance monitoring (CA event logs, Certificate Services Client auto-enrollment auditing) to flag machine/DC-identity certificates issued to unexpected requestors.
  • Adopt least-privilege AD CS template design and periodic ESC (Enrollment Services Component) misconfiguration audits (e.g. with Certipy or PSPKIAudit) covering enrollment-agent, SAN-abuse, and chase-resolution style vectors.
  • Deploy EDR/behavioral detection for DCSync-pattern directory-replication requests (`DsGetNCChanges`) originating from accounts other than known Domain Controllers.
  • Segment and restrict network reachability to Enterprise CA servers so only authorized management and DC hosts can reach the CA's enrollment endpoints and Netlogon service.

CVEs associated with CVE-2026-54121 ("Certighost")

CVE-2026-54121

Weaknesses (CWE) in CVE-2026-54121 ("Certighost")

CWE-285

Timeline of CVE-2026-54121 ("Certighost")

  • Researchers H0j3n and Aniq Fakhrul report the AD CS chase-resolution flaw to Microsoft.
  • Microsoft confirms the vulnerability and assigns it for remediation, later cataloged as CVE-2026-54121.
  • CrowdStrike publishes its July 2026 Patch Tuesday analysis covering CVE-2026-54121 among the month's fixes, describing it as allowing a low-privileged remote attacker to elevate to Domain-Controller-equivalent privileges with no user interaction and low attack complexity.
  • Zero Day Initiative catalogs CVE-2026-54121 as a Critical AD CS Elevation of Privilege vulnerability in its July 2026 Security Update Review, part of a record 621-CVE Patch Tuesday release.
  • Microsoft Security Response Center publishes the CVE-2026-54121 advisory (CVSS 8.8, CWE-285 Improper Authorization).
  • Microsoft ships the fix as part of July 2026 Patch Tuesday (KB5099536/5099540/5099538/5099535 and July 2026 ESU), adding CRequestInstance::_ValidateChaseTargetIsDC to certpdef.dll.
  • SentinelOne's vulnerability database records CVE-2026-54121 with an EPSS exploitation-probability score of 0.80%.
  • NVD's CVE-2026-54121 record is last-modified with finalized CVSS 3.1 scoring (8.8) and affected-product CPE data.
  • Microsoft Threat Intelligence publishes an advisory thread on X and a warning via Bluesky, confirming exploitation requires network access and a valid domain account (but no admin privileges or user interaction) and noting observed security-researcher testing activity.
  • The Hacker News publishes "Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller," bringing the flaw to broad security-community attention.
  • H0j3n publishes a detailed technical analysis gist documenting the chase/cdc/rmd relay mechanics and exploitation walkthrough.
  • Aniq Fakhrul publishes the working "certighost.py" exploitation tool on GitHub (aniqfakhrul/CVE-2026-54121), automating rogue-DC certificate issuance and Kerberos credential extraction.
  • SOC Prime catalogues Sigma detection content for CertiGhost, including rules for rogue LDAP/SMB listener detection, suspicious computer-account creation, and anomalous ADCS-service outbound connections.
  • Nextron Systems authors Sigma rules for the Certighost chase (rule date 2026-07-27), including certificate issued via CDC chase (EventID 4887).
  • Help Net Security reports that Microsoft's initial 'less likely to be exploited' rating may warrant reassessment given the public PoC, while reiterating no confirmed in-the-wild exploitation to date.
  • Help Net Security and other outlets explicitly confirm no in-the-wild exploitation of CVE-2026-54121 has been observed and the CVE does not yet appear in CISA's KEV catalog, though Dataminr threat-intel commentary flags the technique as attractive to ransomware affiliates for post-compromise privilege escalation.
  • BleepingComputer and Help Net Security join The Hacker News in publishing coverage of the public PoC release, broadening media attention beyond the initial 2026-07-24 reporting.
  • Community contributors GregDurys (Netlogon-authentication fix) and Hack0ura (certificate request-SAN fix) submit and get merged reliability improvements to the public certighost.py repository, making the PoC more robust against real-world AD environments.
  • Nextron publishes seven-rule Sigma coverage across the full attack chain (ghost account 4741, non-DC cdc request 4886, certsrv.exe outbound 389/445, issuance 4887, DC TGT 4768, TGS 4769, network logon 4624); SigmaHQ PR #6190 opened for the August release.

Update history for TL-2026-1675

Sources cited for CVE-2026-54121 ("Certighost")

Detection coverage for TL-2026-1675

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1675 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
43 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats