CVE Tools
Back to feed
PoC public Active Directory Certificate Services privilege-escalation Windows Server Microsoft web-app

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Help Net Security·By Zeljka Zorz··3 min read
CVE Tools coverage

A proof-of-concept (PoC) exploit has been published for CVE-2026-54121, a high-severity privilege escalation vulnerability in Microsoft's Active Directory Certificate Services (AD CS). The flaw allows an authenticated attacker to forge certificates and impersonate domain controllers, potentially leading to full domain compromise. Researchers disclosed the issue in May 2026, and Microsoft issued patches on July 14, 2026. However, the release of the PoC raises concerns about potential real-world exploitation. Administrators are urged to apply updates or use mitigation strategies such as registry changes to disable the vulnerable fallback behavior.