← Back to Feed

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121

August 17, 2026 · BleepingComputer · Severity: HIGH

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.

Key Takeaways

  • CVE-2026-54121 enables standard domain users to escalate privileges and impersonate a Domain Controller through the Enterprise Certificate Authority.
  • The vulnerability highlights that patching alone is insufficient when underlying architectural trust assumptions remain unaddressed in PKI deployments.
  • Organizations must treat Active Directory Certificate Services as Tier 0 identity infrastructure equivalent to domain controllers themselves.
☕ Buy a Coffee