← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 27, 2026 · 11:12via AboutDFIR

Infosec News Nuggets — July 27, 2026

Brief

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers published a working exploit on July 24 for a flaw dubbed Certighost that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine, then use the resulting Kerberos credential to pull the krbtgt secret through DCSync and take over an entire domain. Tracked as CVE-2026-54121 with a CVSS score of 8.

8, the bug lives in an AD CS enrollment fallback that let a certification authority trust a requester-supplied directory server without first confirming it was a real Domain Controller. Microsoft patched the issue on July 14, and organizations running an Enterprise CA are urged to apply that update on AD CS hosts, since exploitation needs only network access and a standard domain account.

Read more on AboutDFIR