🚨 Low-privileged Active Directory user → Full Domain Admin? A new AD CS vulnerability called Certighost (CVE-2026-54121) makes it possible. The attack abuses the certificate enrollment "chase" mechanism to obtain a Domain Controller certificate, authenticate via PKINIT, perform DCSync, and ultimately extract the krbtgt secret for complete Active Directory compromise. ✅ No admin privileges required ✅ Public PoC available ✅ Patched by Microsoft, but unpatched Enterprise CAs remain at risk I break down: • How the exploit works internally • Why AD CS trusts the wrong host • PKINIT → DCSync attack chain • Microsoft's patch and new validation logic • Detection and mitigation guidance 🔗 https://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/ #CyberSecurity #ActiveDirectory #ADCS #WindowsServer #Microsoft #PKINIT #Kerberos #DCSync #CVE202654121 #CVE #BlueTeam #RedTeam #ThreatDetection #InfoSec #SOC #Windows #Pentest #DFIR #CyberDefense