Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft AD CS security update for CVE-2026-54121

Security Patch Release
First reported
Last updated
Happening score
H score 34
2 unique sources, 2 articles

Summary

Hide ▲

Certighost (CVE-2026-54121) is a Windows Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker manipulate certificate enrollment and impersonate a machine account or even a Domain Controller in a Windows domain. Microsoft fixed the flaw in the July 2026 Patch Tuesday updates, and the released proof-of-concept exploit shows abuse of attacker-controlled SMB, LSA, and LDAP services, authentication via PKINIT, and follow-on DCSync to recover krbtgt credentials. A temporary mitigation exists for admins who cannot patch immediately, but it disables the optional chase fallback and is described as only a stopgap.

Related Happenings

Microsoft YellowKey patch release (CVE-2026-45585)

Security Patch Release
H score20 First: 11.06.2026 20:43 Last: 11.06.2026 20:43 Sources 1

About this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...

Windows 10 KB5094127 extended security update

Security Patch Release
H score10 First: 09.06.2026 21:35 Last: 09.06.2026 21:35 Sources 1

About this happening: Microsoft released Windows 10 KB5094127 for Windows 10 Enterprise LTSC and ESU-enrolled devices, delivering the June 2026 Patch Tuesday security fixes and extendin...

CCB urgent patch warning for CVE-2026-41089 on Windows servers

Public Sector Action
H score48 First: 01.06.2026 15:30 Last: 01.06.2026 15:30 Sources 1

About this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...

Microsoft security patch release for CVE-2026-45659

Security Patch Release
H score23 First: 26.05.2026 14:49 Last: 26.05.2026 14:49 Sources 1

About this happening: Microsoft released SharePoint updates for CVE-2026-45659, a remote code execution flaw that could let an authenticated attacker run code over the network without eleva...

TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926

Security Patch Release
H score45 First: 22.05.2026 11:19 Last: 22.05.2026 11:19 Sources 1

About this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....

Timeline

  1. 24.07.2026 17:15 3 articles · 13d ago

    Microsoft patches CVE-2026-54121 in Active Directory Certificate Services

    Mitigation Patch Update

    Microsoft released the July 14 update for Active Directory Certificate Services that patched CVE-2026-54121, an improper-authorization flaw that could let a low-privileged Active Directory user obtain a certificate for a Domain Controller and use that credential path for DCSync.

    Show sources
  2. 24.07.2026 17:15 1 articles · 13d ago

    Researchers publish Certighost exploit for AD CS Domain Controller impersonation

    Initial Disclosure

    Researchers H0j3n and Aniq Fakhrul publicly disclosed Certighost on July 24 and published a working exploit for CVE-2026-54121 in Microsoft Active Directory Certificate Services, showing how a low-privileged Active Directory user can obtain a certificate for a Domain Controller and authenticate as that machine.

    Show sources