Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
July 28, 2026
Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's Active Directory Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment. The flaw was present due to a defective trust boundary within the certificate-based client authentication aspect of Microsoft AD Services.
In its July raft of a record 622 Patch Tuesday updates, Microsoft patched a flaw tracked as CVE-2026-54121, which the researchers who discovered and exploited it — Aniq Fakhrul (@aniqfakhrul) and Muhammad Ali (@h0j3n) — called "Certighost," according to a post by the researchers on GitHub.
As the researchers described, the vulnerability affects the enterprise certificate authority's (CA) handling of an AD CS enrollment fallback mechanism known as a "chase," which is a second directory lookup performed in some cross-domain controller enrollment scenarios.








