PoC public Active Directory Certificate Services privilege-escalation Microsoft auth-bypass
Certighost and the Privilege Hiding in Your Certificate Authority
CVE Tools coverage
Researchers have made a proof-of-concept available for "Certighost" (CVE-2026-54121), a vulnerability in Microsoft Active Directory Certificate Services that enables privilege escalation. By exploiting a defect in the "chase" enrollment process, standard domain users can coerce an Enterprise CA into issuing valid authentication certificates for a Domain Controller, granting full control over the domain's identity infrastructure.
Microsoft resolved this issue on July 14, 2026, assigning it a CVSS score of 8.8. Organizations are urged to apply the patch immediately and also review their default configuration, particularly by setting the MachineAccountQuota to zero, to mitigate further reliance on insecure defaults.