In short: A publicly available exploit for Certighost enables domain hijacking via Windows AD Certificate Services by authenticated attackers.
A working proof-of-concept exploit for the Certighost vulnerability in Windows Active Directory Certificate Services is now available, allowing authenticated attackers to take over Windows domains.
A proof-of-concept exploit for the Certighost vulnerability in Windows Active Directory Certificate Services (AD CS) has been published. The vulnerability allows an authenticated attacker to assume complete control over a Windows domain under certain conditions.
For CISOs, this represents an immediate risk to infrastructure: the availability of a practical exploit significantly lowers the technical bar for a successful attack. While exploitation initially requires authenticated access — for example through a compromised standard user or an insider — it can lead to full domain control and thus access to sensitive systems and data.
CISOs should immediately review their AD CS infrastructure for security updates, audit Certificate Services configurations, and check for risky delegations. In parallel, monitoring suspicious certificate requests and issuances is recommended.
Source: www.bleepingcomputer.com · Published July 27, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.