bleeping-computer · Crawled Jul 27, 2026
New Certighost PoC exploit lets attackers hijack Windows domains
2 IoCs
Read original article ↗
AI Summary
A proof-of-concept exploit for the 'Certighost' vulnerability (CVE-2026-54121) in Windows Active Directory Certificate Services has been released, enabling authenticated attackers to hijack Windows domains. The vulnerability allows a low-privileged domain user to manipulate machine account attributes and obtain a certificate that authenticates as a domain controller via PKINIT. This can lead to full domain compromise through DCSync attacks and theft of critical account credentials such as krbtgt.
AI-extracted · verify before operational use