


Perceptive Security
SOC/SIEM Consultancy

New Certighost PoC exploit lets attackers hijack Windows domains
Published:
27 juli 2026 om 21:00:25
Alert date:
27 juli 2026 om 22:00:55
Source:
bleepingcomputer.com
Operating Systems, Zero-Day Vulnerabilities, Identity & Access
A proof-of-concept exploit dubbed 'Certighost' has been released targeting a vulnerability in Windows Active Directory Certificate Services (AD CS). The exploit allows authenticated attackers to potentially compromise and hijack an entire Windows domain. The release of a public PoC significantly lowers the barrier for threat actors to exploit the vulnerability. AD CS vulnerabilities are considered high-value targets as they can enable full domain compromise. Organizations running Windows domains with AD CS are advised to patch and monitor for exploitation attempts. The vulnerability follows a pattern of similar AD CS attack techniques that have been increasingly targeted in recent years.
Technical details
Mitigation steps:
Affected products:
Windows Active Directory Certificate Services
Windows Active Directory
Related links:
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-54121
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
http://github.com/aniqfakhrul/CVE-2026-54121
Related CVE's:
Related threat actors:
IOC's:
certighost.py proof-of-concept tool (github.com/aniqfakhrul/CVE-2026-54121), Kerberos .ccache credential files generated via PKINIT authentication as domain controller, DCSync activity targeting krbtgt account credentials, Rogue SMB, LSA, and LDAP services on non-domain-controller hosts, Certificate requests containing attacker-controlled 'cdc' and 'rmd' attributes directed to non-legitimate domain controllers, Machine account creation via ms-DS-MachineAccountQuota by low-privileged users prior to certificate abuse
This article was created with the assistance of AI technology by Perceptive.
