← Back to Feed

'Certighost' Flaw Haunts Microsoft Active Directory Certificates

July 28, 2026 · Dark Reading · Severity: HIGH

Microsoft patched a high-severity vulnerability in Active Directory Certificate Services (AD CS) that could enable attackers to conduct certificate-based attacks against domain environments. The Certighost flaw, as it came to be known, threatened the foundation of certificate-based authentication in Active Directory, potentially allowing adversaries to forge certificates, escalate privileges, or impersonate domain entities. Since AD CS underpins smart card authentication, VPN certificates, code signing, and Windows Hello for Business, exploitation could give attackers persistent, cryptographically trusted access that bypasses traditional password and MFA controls entirely.

Key Takeaways

  • Microsoft patched a high-severity AD CS vulnerability called Certighost affecting certificate-based authentication in Active Directory.
  • The flaw could allow certificate forgery, privilege escalation, and domain entity impersonation.
  • AD CS underpins critical infrastructure including smart cards, VPN auth, code signing, and Windows Hello for Business.
  • Exploitation bypasses password and MFA controls because certificate-based trust does not rely on them.
  • Organizations must prioritize AD CS patching and audit certificate issuance policies for signs of abuse.
☕ Buy a Coffee