4

cross-posted from: https://lemmy.world/post/49907053

A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) shows just how dangerous certificate-based authentication can become when trust breaks down. Certighost (CVE-2026-54121) allows a low-privileged domain user, under specific conditions, to obtain a certificate for a Domain Controller, authenticate using PKINIT, and perform DCSync to retrieve the krbtgt secret, potentially leading to complete Active Directory compromise. Microsoft patched the flaw in its July 2026 security updates, but a public proof-of-concept is now available

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here
this post was submitted on 26 Jul 2026
4 points (100.0% liked)

Microsoft

960 readers
1 users here now

founded 3 years ago
MODERATORS