bleeping-computer · Crawled Jul 27, 2026

New Certighost PoC exploit lets attackers hijack Windows domains

2 IoCs
Read original article ↗

AI Summary

A proof-of-concept exploit for the 'Certighost' vulnerability (CVE-2026-54121) in Windows Active Directory Certificate Services has been released, enabling authenticated attackers to hijack Windows domains. The vulnerability allows a low-privileged domain user to manipulate machine account attributes and obtain a certificate that authenticates as a domain controller via PKINIT. This can lead to full domain compromise through DCSync attacks and theft of critical account credentials such as krbtgt.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
GitHub Repo h0j3n/Certighost Details →
Filename certighost.py Details →