A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
Tracked as CVE-2026–54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates.
“An authenticated attacker could manipulate attributes associated with a machine account and obtain a certificate from Active Directory Certificate Services that allows authentication as that machine via PKINIT,” Microsoft explained.
