Microsoft AD CS security update for CVE-2026-54121
Security Patch Release
Summary
Hide ▲
Show ▼
Certighost (CVE-2026-54121) is a Windows Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker manipulate certificate enrollment and impersonate a machine account or even a Domain Controller in a Windows domain. Microsoft fixed the flaw in the July 2026 Patch Tuesday updates, and the released proof-of-concept exploit shows abuse of attacker-controlled SMB, LSA, and LDAP services, authentication via PKINIT, and follow-on DCSync to recover krbtgt credentials. A temporary mitigation exists for admins who cannot patch immediately, but it disables the optional chase fallback and is described as only a stopgap.
Related Happenings
Microsoft YellowKey patch release (CVE-2026-45585)
Security Patch Release
H score20
First: 11.06.2026 20:43
Last: 11.06.2026 20:43
Sources 1
About this happening:
Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...
Microsoft YellowKey patch release (CVE-2026-45585)
Security Patch ReleaseAbout this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...
Windows 10 KB5094127 extended security update
Security Patch Release
H score10
First: 09.06.2026 21:35
Last: 09.06.2026 21:35
Sources 1
About this happening:
Microsoft released Windows 10 KB5094127 for Windows 10 Enterprise LTSC and ESU-enrolled devices, delivering the June 2026 Patch Tuesday security fixes and extendin...
Windows 10 KB5094127 extended security update
Security Patch ReleaseAbout this happening: Microsoft released Windows 10 KB5094127 for Windows 10 Enterprise LTSC and ESU-enrolled devices, delivering the June 2026 Patch Tuesday security fixes and extendin...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Microsoft security patch release for CVE-2026-45659
Security Patch Release
H score23
First: 26.05.2026 14:49
Last: 26.05.2026 14:49
Sources 1
About this happening:
Microsoft released SharePoint updates for CVE-2026-45659, a remote code execution flaw that could let an authenticated attacker run code over the network without eleva...
Microsoft security patch release for CVE-2026-45659
Security Patch ReleaseAbout this happening: Microsoft released SharePoint updates for CVE-2026-45659, a remote code execution flaw that could let an authenticated attacker run code over the network without eleva...
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch Release
H score45
First: 22.05.2026 11:19
Last: 22.05.2026 11:19
Sources 1
About this happening:
TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch ReleaseAbout this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
Timeline
-
24.07.2026 17:15 3 articles · 13d ago
Microsoft patches CVE-2026-54121 in Active Directory Certificate Services
Mitigation Patch UpdateMicrosoft released the July 14 update for Active Directory Certificate Services that patched CVE-2026-54121, an improper-authorization flaw that could let a low-privileged Active Directory user obtain a certificate for a Domain Controller and use that credential path for DCSync.
Show sources
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15
- New Certighost PoC exploit lets attackers hijack Windows domains — www.bleepingcomputer.com — 28.07.2026 00:00
-
24.07.2026 17:15 1 articles · 13d ago
Researchers publish Certighost exploit for AD CS Domain Controller impersonation
Initial DisclosureResearchers H0j3n and Aniq Fakhrul publicly disclosed Certighost on July 24 and published a working exploit for CVE-2026-54121 in Microsoft Active Directory Certificate Services, showing how a low-privileged Active Directory user can obtain a certificate for a Domain Controller and authenticate as that machine.
Show sources
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller — thehackernews.com — 24.07.2026 17:15