CVE-2026-54121

HIGH

Microsoft Windows 10 Version 1607 - Active Directory Certificate Services Elevation of Privilege Vulnerability

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2026-54121. PoCs published by aniqfakhrul, ChPratik, marcgoam.

AI-analyzed exploit summary This PoC exploits CVE-2026-54121 (Certighost), a certificate-based authentication bypass in Active Directory Certificate Services (AD CS). The exploit creates a rogue computer account, then uses malicious LDAP/SMB listeners to trick a Certificate Authority (CA) into issuing a certificate impersonating a domain controller, enabling Kerberos authentication as the DC.

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Exploits (7)

github WORKING POC 4 stars
by aniqfakhrul · pythonpoc
https://github.com/aniqfakhrul/CVE-2026-54121

This PoC exploits CVE-2026-54121 (Certighost), a certificate-based authentication bypass in Active Directory Certificate Services (AD CS). The exploit creates a rogue computer account, then uses malicious LDAP/SMB listeners to trick a Certificate Authority (CA) into issuing a certificate impersonating a domain controller, enabling Kerberos authentication as the DC.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Complex
Reliability
Reliable
Target: Microsoft Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: Valid low-privilege domain credentials · Network access to a Domain Controller and Certificate Authority · Ability to create computer accounts (or reuse an existing one) · Privileged ports (389, 445) available for rogue listeners
mistral-large-3 · analyzed Jul 24, 2026 Full analysis →
github WRITEUP
by ChPratik · poc
https://github.com/ChPratik/CVE-2026-54121

This repository provides an in-depth technical analysis of CVE-2026-54121 (Certighost), an Active Directory Certificate Services (AD CS) elevation-of-privilege vulnerability caused by improper authorization in the certificate enrollment chase fallback path. The report includes root cause analysis, patch details, attack prerequisites, detection guidance, and defensive recommendations, but does not contain exploit code.

Classification
Writeup 99%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012-2025
Auth required
Prerequisites: Valid low-privilege domain account · AD CS Enterprise CA reachable by attacker · Machine account creation rights (default in many environments)
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →
github WORKING POC
by marcgoam · pythonpoc
https://github.com/marcgoam/CVE-2026-54121-CertiGhost

This PoC exploits CVE-2026-54121 (CertiGhost), a certificate misissuance vulnerability in Active Directory Certificate Services (AD CS). It manipulates the CA's authentication process via rogue LSA/LDAP servers to issue a valid certificate for a domain controller, impersonating a computer account, enabling Kerberos authentication (PKINIT) as the DC.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Complex
Reliability
Reliable
Target: Microsoft Active Directory Certificate Services (AD CS) on Windows Server (versions not specified)
Auth required
Prerequisites: Low-privileged domain user account with permissions to create computer accounts (ms-DS-MachineAccountQuota > 0) · Network access to Domain Controller (LDAP, SMB, Netlogon) · AD CS server reachable from attacker machine · Python 3 with Impacket, cryptography, pyasn1, asn1crypto, and pycryptodomex libraries
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →
github WRITEUP
by GlendonNotGlen · csspoc
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides

This repository contains a detailed technical writeup of CVE-2026-54121, a vulnerability in Active Directory Certificate Services (AD CS) where a requester-controlled chase target allows a low-privileged user to obtain a Domain Controller certificate. The analysis includes root cause, exploit chain, and validation path details.

Classification
Writeup 98%
Attack Type
Auth Bypass
Complexity
Complex
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: Low-privileged access to AD environment · AD CS with vulnerable configuration · Ability to craft specific certificate enrollment requests
mistral-large-3 · analyzed Jul 26, 2026 Full analysis →
github WORKING POC
by tc4dy · pythonpoc
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit

This exploit targets CVE-2026-54121, a vulnerability in Active Directory Certificate Services (AD CS) enabling domain privilege escalation via crafted certificate requests. The PoC implements a full attack chain including LDAP queries, NTLM authentication, and Kerberos ticket manipulation to compromise domain credentials.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Complex
Reliability
Reliable
Target: Microsoft Active Directory Certificate Services (AD CS)
No auth needed
Prerequisites: Network access to domain controller · Valid domain user account (optional, for some attack paths) · AD CS server with vulnerable configuration
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
github STUB
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-54121

The repository contains no actual exploit code, technical details, or vulnerability analysis for CVE-2026-54121. It only includes a README with donation requests, setup instructions, and legal disclaimers, alongside a generic license file.

Classification
Stub 95%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
github STUB
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-54121

The repository contains only a README.md file with the CVE identifier and no technical details, exploit code, or vulnerability analysis. It serves as a placeholder with minimal content.

Classification
Stub 95%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
Active Directory Certificate Services Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121

Scores

CVSS v3 8.8
EPSS 0.0105
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (21)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.9339
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.9020
Microsoft/Windows Server 2012 6.2.9200.0 - 6.2.9200.26226
Microsoft/Windows Server 2012 (Server Core installation) 6.2.9200.0 - 6.2.9200.26226
Microsoft/Windows Server 2012 R2 6.3.9600.0 - 6.3.9600.23291
Microsoft/Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 - 6.3.9600.23291
Microsoft/Windows Server 2016 10.0.14393.0 - 10.0.14393.9339
Microsoft/Windows Server 2016 (Server Core installation) 10.0.14393.0 - 10.0.14393.9339
Microsoft/Windows Server 2019 10.0.17763.0 - 10.0.17763.9020
Microsoft/Windows Server 2019 (Server Core installation) 10.0.17763.0 - 10.0.17763.9020
... and 11 more
Published Jul 14, 2026
Tracked Since Jul 14, 2026