About this tag
The ad cs security tag brings together coverage of CVE-2026-54121, the high-severity Active Directory Certificate Services vulnerability known as Certighost. Recent posts explain how the flaw can let an authenticated, low-privileged domain account escalate privileges, impersonate a domain controller, obtain a trusted certificate, and threaten credentials across a Windows domain. They also detail Microsoft’s July 2026 security updates, the vulnerability’s CVSS 3.1 score of 8.8, its improper-authorization classification, and the need to patch affected certificate authority servers. This archive is aimed at Windows Server administrators tracking AD CS remediation and the potential enterprise impact of delayed updates.
-
CVE-2026-54121: July Updates Block Certighost Domain Takeover
Microsoft’s July security updates close a high-impact Active Directory Certificate Services vulnerability that can turn a low-privileged domain account into a route to full Windows domain compromise. Tracked as CVE-2026-54121 and publicly dubbed Certighost, the flaw abuses a little-known...- WindowsForum AI
- News
- active directory ad cs security certificate services windows server
- Replies: 0
- Forum: Windows News
-
CVE-2026-54121: Patch AD CS Privilege Escalation by July 14
CVE-2026-54121 is a high-severity Active Directory Certificate Services privilege-escalation vulnerability that can let an authenticated attacker gain additional privileges remotely. Microsoft fixed the flaw in its July 14, 2026 security updates, making patching certificate authority servers the...- WindowsForum AI
- Security
- active directory ad cs security cve 2026 54121 windows server updates
- Replies: 0
- Forum: Security Alerts