Threat reportVulnerabilityTL-2026-1675
CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation
CVE-2026-54121 ("Certighost") (TL-2026-1675), also tracked as Certighost, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-07-24 and last reviewed 2026-10-01. It has no confirmed attribution, affects Microsoft Windows Server (Active Directory Certificate Services role), references 1 CVE (CVE-2026-54121), maps to 28 MITRE ATT&CK techniques (T1003.006, T1018, T1036), and is covered by 9 detection rules and 43 indicators of compromise.
- CVSS
- 8.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 28MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 43Indicators of compromise
Key facts for TL-2026-1675
- Threat ID
- TL-2026-1675
- Also known as
- Certighost
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, manufacturing, education, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 43
- Updates
- 2026-10-01 · 4 updates · revalidated 4× · latest source
Malware and tooling in CVE-2026-54121 ("Certighost")
Malware and tooling: Certighost, Certipy
How CVE-2026-54121 ("Certighost") works
CVE-2026-54121 ("Certighost") is a CVSS 8.8 improper-authorization flaw in Active Directory Certificate Services (AD CS) that lets any authenticated low-privileged domain user relay a Certification Authority's "chase" fallback resolution to impersonate a Domain Controller, obtain a DC-identity certificate, authenticate via PKINIT, and perform DCSync against krbtgt. Microsoft patched it July 14, 2026 (Patch Tuesday); a working public PoC ("certighost.py") was released July 24, 2026 by researchers H0j3n and Aniq Fakhrul.
AD CS Enterprise Certification Authorities support a certificate-enrollment fallback path called a "chase": when the CA cannot directly resolve the identity of the end entity requesting a certificate, the enrollment protocol allows the requester to supply a `cdc` parameter (an Active Directory server/contact point) and an `rmd` parameter (the machine object to resolve) so the CA can go fetch the missing identity attributes itself. Prior to the July 2026 patch, the CA followed the requester-supplied `cdc` host over SMB and LDAP without first proving that host was a genuine Domain Controller.
An attacker holding nothing more than a standard domain account (or a computer account created under the default `ms-DS-MachineAccountQuota` of 10) can stand up rogue SMB (445) and LDAP (389) listener services, submit a certificate enrollment request whose `cdc` attribute points at the attacker's own host and whose `rmd` attribute names the real target Domain Controller, and let the CA's outbound Netlogon authentication challenge be relayed back to the legitimate DC. The rogue listeners respond with the target DC's `objectSid`, `sAMAccountName`, and `dNSHostName`, which the CA then binds into the issued certificate — producing a valid certificate that asserts the *attacker* is the Domain Controller.
That certificate is used to perform PKINIT Kerberos pre-authentication, yielding a TGT (and derivable NT hash / `.ccache`) for the DC's own machine account. Domain Controller machine accounts hold directory-replication rights (`Replicating Directory Changes` / `Replicating Directory Changes All`), so the attacker can immediately run DCSync to extract the `krbtgt` secret and every domain account credential — full domain compromise from a single unprivileged starting foothold, no admin rights and no user interaction required at any step.
Microsoft's July 14, 2026 update closes the gap by adding `CRequestInstance::_ValidateChaseTargetIsDC` to `certpdef.dll`, which rejects IP literals and over-long names, blocks LDAP metacharacters, requires exactly one matching AD computer object, validates DNS-name correspondence, confirms `userAccountControl` contains `SERVER_TRUST_ACCOUNT` (0x2000), and performs a SID comparison before honoring a chase target as a genuine DC.
A fully automated public exploitation tool (`certighost.py`, github.com/aniqfakhrul/CVE-2026-54121) was released July 24, 2026, ten days after the patch, that creates/reuses a rogue computer account, spins up the SMB/LDAP listeners, drives the enrollment/relay flow end-to-end, and drops a `.pfx` certificate plus a `.ccache` ready for immediate Kerberos-based domain impersonation. No confirmed in-the-wild exploitation had been reported as of the July 24, 2026 disclosure, but the combination of a trivial privilege bar (any domain account), zero user interaction, network-only attack vector, and a fully weaponized public PoC makes unpatched AD CS environments an urgent detection and patching priority.
MITRE ATT&CK techniques used in TL-2026-1675
Credential Access
T1003.006 OS Credential Dumping: DCSync; T1187 Forced Authentication; T1212 Exploitation for Credential Access; T1552 Unsecured Credentials; T1557.001 Name Resolution Poisoning and SMB Relay; T1558 Steal or Forge Kerberos Tickets; T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket
Discovery
T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account
Defense Evasion
Execution
T1059.006 Command and Scripting Interpreter: Python
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1098 Account Manipulation
Initial Access
T1078.002 Valid Accounts: Domain Accounts
Persistence
T1136.002 Create Account: Domain Account
defense-impairment
Lateral Movement
T1210 Exploitation of Remote Services; T1550.003 Use Alternate Authentication Material: Pass the Ticket
Impact
Resource Development
T1587.001 Develop Capabilities: Malware; T1587.004 Develop Capabilities: Exploits; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1590.001 Gather Victim Network Information: Domain Properties; T1592.002 Gather Victim Host Information: Software; T1595.002 Active Scanning: Vulnerability Scanning
credential-access
Affected products and versions in CVE-2026-54121 ("Certighost")
- Microsoft — Windows Server (Active Directory Certificate Services role)
Vulnerable versions: Windows Server 2025 (pre-26100.33158); Windows Server 2022 (pre-20348.5386); Windows Server 2019 (pre-17763.9020); Windows Server 2016 (pre-14393.9339); Windows Server 2012 R2 (pre-6.3.9600.23291); Windows Server 2012; Windows 10 version 1607; Windows 10 version 1809
Fixed in: Windows Server 2025 with KB5099536; Windows Server 2022 with KB5099540; Windows Server 2019 with KB5099538; Windows Server 2016 with KB5099535; Windows Server 2012 R2 with July 2026 ESU
Remediation for CVE-2026-54121 ("Certighost")
Patches
- Windows Server 2025 — KB5099536 (build 26100.33158+)
- Windows Server 2022 — KB5099540 (build 20348.5386+)
- Windows Server 2019 — KB5099538 (build 17763.9020+)
- Windows Server 2016 — KB5099535 (build 14393.9339+)
- Windows Server 2012 R2 — July 2026 Extended Security Updates (build 6.3.9600.23291+)
Immediate actions
- Install Microsoft's July 14, 2026 security updates on every host running the AD CS Certification Authority role (KB5099536 / KB5099540 / KB5099538 / KB5099535 or the July 2026 ESU for Server 2012 R2, as applicable to the OS version).
- Inventory all Enterprise CAs and confirm the patched `certpdef.dll` build (containing `CRequestInstance::_ValidateChaseTargetIsDC`) is installed and `CertSvc` has been restarted to load it.
- Audit and reduce `ms-DS-MachineAccountQuota` from the default value of 10 to 0 where computer self-provisioning by standard users is not required.
- Monitor for anomalous new computer-account creation events (Event ID 4741) and unexpected inbound SMB (445) / LDAP (389) service bindings from non-DC domain-joined hosts.
Workarounds
- Lab-tested-only temporary mitigation: `certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC` followed by `Restart-Service CertSvc -Force` to disable chase-client-DC resolution entirely. Researchers explicitly warn this can break legitimate enrollment flows and should be staged/tested before production use, and treated only as a bridge to the official patch, never a permanent fix.
Longer-term hardening
- Deploy AD CS enrollment auditing and certificate-issuance monitoring (CA event logs, Certificate Services Client auto-enrollment auditing) to flag machine/DC-identity certificates issued to unexpected requestors.
- Adopt least-privilege AD CS template design and periodic ESC (Enrollment Services Component) misconfiguration audits (e.g. with Certipy or PSPKIAudit) covering enrollment-agent, SAN-abuse, and chase-resolution style vectors.
- Deploy EDR/behavioral detection for DCSync-pattern directory-replication requests (`DsGetNCChanges`) originating from accounts other than known Domain Controllers.
- Segment and restrict network reachability to Enterprise CA servers so only authorized management and DC hosts can reach the CA's enrollment endpoints and Netlogon service.
CVEs associated with CVE-2026-54121 ("Certighost")
Weaknesses (CWE) in CVE-2026-54121 ("Certighost")
Timeline of CVE-2026-54121 ("Certighost")
- Researchers H0j3n and Aniq Fakhrul report the AD CS chase-resolution flaw to Microsoft.
- Microsoft confirms the vulnerability and assigns it for remediation, later cataloged as CVE-2026-54121.
- CrowdStrike publishes its July 2026 Patch Tuesday analysis covering CVE-2026-54121 among the month's fixes, describing it as allowing a low-privileged remote attacker to elevate to Domain-Controller-equivalent privileges with no user interaction and low attack complexity.
- Zero Day Initiative catalogs CVE-2026-54121 as a Critical AD CS Elevation of Privilege vulnerability in its July 2026 Security Update Review, part of a record 621-CVE Patch Tuesday release.
- Microsoft Security Response Center publishes the CVE-2026-54121 advisory (CVSS 8.8, CWE-285 Improper Authorization).
- Microsoft ships the fix as part of July 2026 Patch Tuesday (KB5099536/5099540/5099538/5099535 and July 2026 ESU), adding CRequestInstance::_ValidateChaseTargetIsDC to certpdef.dll.
- SentinelOne's vulnerability database records CVE-2026-54121 with an EPSS exploitation-probability score of 0.80%.
- NVD's CVE-2026-54121 record is last-modified with finalized CVSS 3.1 scoring (8.8) and affected-product CPE data.
- Microsoft Threat Intelligence publishes an advisory thread on X and a warning via Bluesky, confirming exploitation requires network access and a valid domain account (but no admin privileges or user interaction) and noting observed security-researcher testing activity.
- The Hacker News publishes "Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller," bringing the flaw to broad security-community attention.
- H0j3n publishes a detailed technical analysis gist documenting the chase/cdc/rmd relay mechanics and exploitation walkthrough.
- Aniq Fakhrul publishes the working "certighost.py" exploitation tool on GitHub (aniqfakhrul/CVE-2026-54121), automating rogue-DC certificate issuance and Kerberos credential extraction.
- SOC Prime catalogues Sigma detection content for CertiGhost, including rules for rogue LDAP/SMB listener detection, suspicious computer-account creation, and anomalous ADCS-service outbound connections.
- Nextron Systems authors Sigma rules for the Certighost chase (rule date 2026-07-27), including certificate issued via CDC chase (EventID 4887).
- Help Net Security reports that Microsoft's initial 'less likely to be exploited' rating may warrant reassessment given the public PoC, while reiterating no confirmed in-the-wild exploitation to date.
- Help Net Security and other outlets explicitly confirm no in-the-wild exploitation of CVE-2026-54121 has been observed and the CVE does not yet appear in CISA's KEV catalog, though Dataminr threat-intel commentary flags the technique as attractive to ransomware affiliates for post-compromise privilege escalation.
- BleepingComputer and Help Net Security join The Hacker News in publishing coverage of the public PoC release, broadening media attention beyond the initial 2026-07-24 reporting.
- Community contributors GregDurys (Netlogon-authentication fix) and Hack0ura (certificate request-SAN fix) submit and get merged reliability improvements to the public certighost.py repository, making the PoC more robust against real-world AD environments.
- Nextron publishes seven-rule Sigma coverage across the full attack chain (ghost account 4741, non-DC cdc request 4886, certsrv.exe outbound 389/445, issuance 4887, DC TGT 4768, TGS 4769, network logon 4624); SigmaHQ PR #6190 opened for the August release.
Update history for TL-2026-1675
- 2026-10-01 — Certighost (CVE-2026-54121): ADCS Domain Controller Impersonation via CDC Chase, Public PoC and Sigma Coverage: What changed No severity, exploitability or status change; still POC_PUBLIC with no confirmed in-the-wild exploitation or CISA KEV listing. New indicators (9) 9 new behavioral/tool/URL indicators: CA registry check and audit-filter commands
- 2026-07-28 — CertiGhost (CVE-2026-54121): AD CS Certificate-Chase Flaw Lets Low-Privileged Users Impersonate a Domain Controller: What changed No severity/exploitability/status escalation — CVSS 8.8, POC_PUBLIC exploitability, and PATCHED status all unchanged. The update adds a third credited co-reporter, internal AD CS code-path/feature-gate detail, a Microsoft Threa
- 2026-07-28 — CertiGhost (CVE-2026-54121): PoC Exploit Released for Critical AD CS Domain-Takeover Flaw: What changed No severity/exploitability/status escalation — the newer report's 'status: ACTIVE' label is unsupported (the same report states no confirmed ITW exploitation) and does not override this record's evidence-based 'PATCHED' status.
- 2026-07-27 — Certighost PoC Exploit (CVE-2026-54121) Enables Windows Active Directory Domain Takeover via AD CS 'Chase' Fallback Abuse: What changed No field-level escalation is warranted: CVSS (8.8), severity (CRITICAL), exploitability (POC_PUBLIC), and attribution (Unattributed/LOW) are unchanged and evidenced identically in both reports. The newer report's 'status: ACTIV
Sources cited for CVE-2026-54121 ("Certighost")
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
- GitHub - aniqfakhrul/CVE-2026-54121: Certighost POC
- Microsoft Security Update Guide - CVE-2026-54121
- NVD Vulnerability Record - CVE-2026-54121
- CISA Known Exploited Vulnerabilities Catalog
- Zero Day Initiative — The July 2026 Security Update Review
- Microsoft's July 2026 Update Fixes Active Directory Certificate Services Flaw That Allows Remote Takeover
- Certighost technical analysis gist (H0j3n)
- Certipy — AD CS attack/audit framework (referenced tooling)
Detection coverage for TL-2026-1675
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1675 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.