Security · 1h ago
New PoC Exploit Lets Low-Privilege Users Hijack Windows Domains via AD CS
A public proof-of-concept exploit for CVE-2026-54121 allows attackers with a low-privilege domain account to impersonate a Domain Controller by tricking Active Directory Certificate Services. The attack chains LDAP, fake services, and PKINIT to achieve full domain takeover via DCSync. Microsoft's July 2026 patch blocks the vulnerability, but unpatched systems remain at risk.
Meridian48 take
The exploit's simplicity and low barrier to entry make it a critical threat for enterprises that haven't applied the July 2026 security update.
Read the full reporting
Certighost CVE-2026-54121: Low-Privilege Users Impersonate a DC via AD CS →
DEV Community
cve-2026-54121ad-cs-exploit