Skip to content

PoC for Active Directory Vulnerability Certighost Published

In summary: CVE-2026-54121 allows regular AD users to elevate privileges and is immediately exploitable via publicly available PoC.

The Active Directory vulnerability CVE-2026-54121 (Certighost) was patched on 14 July 2026, but since 24 July a public proof of concept has been available — with detailed technical documentation.

The Active Directory vulnerability CVE-2026-54121, named Certighost, allows standard AD users to escalate their privileges within the domain. Microsoft released a patch on 14 July 2026.

Since 24 July 2026, the security community has published a functioning proof of concept as well as comprehensive technical documentation for exploitation. This significantly reduces the timespan between patch and practical exploitability.

For CISOs, this means increased capabilities on the attack side: regular users with weak privileges become a potential entry point for lateral movement in the infrastructure. Prioritised inventory and patch management processes for AD-critical systems should already be completed; if not, immediate validation of patch status is required. To reduce risk, monitoring of certificate abuse and defense-in-depth controls help limit privilege escalation.


Source: borncity.com · Published 27 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: