ON
← Back to feed
Microsoft: Proof-of-concept exploit for ertiCertighostAD AD vulnerability has been discovered
Germany💻 Technology9 hr. ago

Microsoft: Proof-of-concept exploit for ertiCertighostAD AD vulnerability has been discovered

Microsoft has warned administrators about the emergence of proof-of-concept exploit code for a critical vulnerability in its Active Directory Certificate Services (AD CS), known as 'Certighost' (CVE-2026-54121). This vulnerability allows authenticated users to manipulate machine account attributes and obtain certificates that enable authentication as a domain controller, potentially allowing attackers to perform unauthorized AD operations. The vulnerability was patched during Microsoft’s July security update, but the release of detailed exploit code increases the risk of attacks. Microsoft recommends immediate installation of the July patches, especially on servers hosting Enterprise Certification Authorities, to prevent exploitation. Additionally, administrators who cannot apply updates immediately are advised to enable audit logging to detect suspicious certificate-related activities.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenter9 hr. ago
Microsoft: Proof-of-concept exploit for ertiCertighostAD AD vulnerability has been discovered

Microsoft has warned administrators about the emergence of proof-of-concept exploit code for a critical vulnerability in its Active Directory Certificate Services (AD CS), known as 'Certighost' (CVE-2026-54121). This vulnerability allows authenticated users to manipulate machine account attributes and obtain certificates that enable authentication as a domain controller, potentially allowing attackers to perform unauthorized AD operations. The vulnerability was patched during Microsoft’s July security update, but the release of detailed exploit code increases the risk of attacks. Microsoft recommends immediate installation of the July patches, especially on servers hosting Enterprise Certification Authorities, to prevent exploitation. Additionally, administrators who cannot apply updates immediately are advised to enable audit logging to detect suspicious certificate-related activities.

Bias read (Center): The article focuses on a technical vulnerability in Microsoft's software and provides factual information about the exploit, mitigation strategies, and recommendations from Microsoft. There is no political framing, bias, or ideological emphasis present in the content.

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories