CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3263

As cited

Copy frozen at (site build).

vulnerabilities

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Security researchers have released a proof-of-concept exploit and technical details for CVE-2026-54121 (Certighost), a critical privilege escalation vulnerability affecting Microsoft Active Directory Certificate Services. The flaw impacts the AD CS role in Windows Server, which manages digital certificates for authentication, encryption, and signing operations across an organization.

Why it matters: Organizations running AD CS are at immediate risk of domain compromise through privilege escalation; patch or restrict access to vulnerable AD CS servers without delay, and monitor for exploitation attempts given public exploit availability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Security researchers have released a proof-of-concept exploit and technical details for CVE-2026-54121 (Certighost), a critical privilege escalation vulnerability affecting Microsoft Active Directory Certificate Services. The flaw impacts the AD CS role in Windows Server, which manages digital certificates for authentication, encryption, and signing operations across an organization.

Why it matters: Organizations running AD CS are at immediate risk of domain compromise through privilege escalation; patch or restrict access to vulnerable AD CS servers without delay, and monitor for exploitation attempts given public exploit availability.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary