CVE detail
CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
14 source links · newest first
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has a
newswww.bleepingcomputer.comAug 17, 2026, 2:00 PMt of Microsoft AD Services. In its July raft of a record 622 Patch Tuesday updates, Microsoft patched a flaw tracked as CVE-2026-54121 , which the researchers who discovered and exploited it — Aniq Fakhrul ( @aniqfakhrul ) and Muhammad Ali ( @h0j3n ) — called "Certighost," according to a post by the researchers on GitHub. As the researchers described,
newswww.darkreading.comJul 28, 2026, 4:38 PM- New Certighost PoC exploit lets attackers hijack Windows domainsBleepingComputer
bility, has been released that can allow authenticated attackers to potentially compromise a Windows domain. Tracked as CVE-2026-54121 , the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates. "An authenticated attacker could manipulate attributes associated with a machine account and obtain a certificate from
newswww.bleepingcomputer.comJul 27, 2026, 9:00 PM - ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News
products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful
newsthehackernews.comJul 27, 2026, 2:10 PM Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulner
newswww.helpnetsecurity.comJul 27, 2026, 12:04 PM- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerThe Hacker News
t secret through DCSync . Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as CVE-2026-54121 . Microsoft classed the flaw as improper authorization and assigned it a CVSS score of 8.8. Exploitation requires network access and a domain account, but no administrator rights or user interaction. In the researchers'
newsthehackernews.comJul 24, 2026, 2:15 PM - July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-DaysCrowdStrike
t families affected by July 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Active Directory Federation Services CVE-2026-56155 is an Important elevation of privilege vulnerability affecting Active Directory Federation Services (AD FS) and has a CVSS score of 7.8 . An insufficient granularity of access control flaw (CWE-1220) allows a low-privil
vendorwww.crowdstrike.comJul 17, 2026, 8:00 PM patched, including two that have been exploited in the wild. Those two are both elevation of privilege vulnerabilities: CVE-2026-56155, an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and CVE-2026-56164 , a Microsoft SharePoint Server vulnerability. The third is CVE-
newswww.csoonline.comJul 15, 2026, 1:54 AMation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i
vendorwww.rapid7.comJul 14, 2026, 10:00 PMication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in July Patch Tuesday Edition CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability Insufficient granularity of access control in Active Directory Federation Services (AD FS) could allow an authenticated attacker to elevate priv
vendorblog.qualys.comJul 14, 2026, 9:23 PMed as "critical." Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileg
vendorblog.talosintelligence.comJul 14, 2026, 8:27 PMile no official fix is available. The two actively exploited zero-days addressed during this month's Patch Tuesday are: CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in Active Directory Federation Services that grants administrative privileges. "Insuf
newswww.bleepingcomputer.comJul 14, 2026, 6:01 PM- The July 2026 Security Update ReviewZero Day Initiative
oser look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild. - CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-contro
vendorwww.thezdi.comJul 14, 2026, 5:56 PM - CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege VulnerabilityMicrosoft MSRC
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
vendormsrc.microsoft.comJul 14, 2026, 2:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-58540CVSS 7.8 · High
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-50346CVSS 7.8 · High
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50344CVSS 7.8 · High
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
- CVE-2023-21549CVSS 8.8 · High
Windows SMB Witness Service Elevation of Privilege Vulnerability
- CVE-2026-70354CVSS 7.8 · High
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-70347CVSS 7.8 · High
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.