A critical privilege elevation vulnerability (CVE-2026-54121, CVSS 8.8) in Active Directory Certificate Services (AD CS), dubbed "Certighost," allows for domain takeover, and a public proof-of-concept exploit has been released. Affected versions include Windows 10 1607 prior to 10.0.14393.9339, Windows 10 1809 prior to 10.0.17763.9020, and other Windows Server versions as listed in the NVD data. The fixed versions are 10.0.14393.9339, 10.0.17763.9020, 10.0.20348.5386, and 10.0.26100.33158 for their respective Windows builds.
Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is a Microsoft Windows Server role that lets an organization run its own Public Key Infrastructure (PKI). It acts as a Certificate Authority (CA), issuing and managing digital certificates used for authentication, encryption, and signing across … More → The post PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) appeared first on Help Net Security .