Wire · regulatory
New Certighost PoC exploit lets attackers hijack Windows domains
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
A proof-of-concept exploit for CVE-2026-54121 (Certighost), a Windows Active Directory Certificate Services vulnerability, has been publicly released, allowing authenticated attackers to impersonate domain controllers and compromise entire Windows domains. Microsoft patched the flaw in July 2026 Patch Tuesday updates.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 3 sources have reported it between 24 Jul 2026 and 28 Jul 2026.
◆ ◆ The Wire takeaway
If your product runs on Windows domains or manages Active Directory, your customers are now a single misconfigured certificate request away from total compromise. The patch is out, but the exploit is public - your sales and support teams need to confirm every customer has applied it before end of week.
◆ Coverage
3 sources · first reported 24 Jul 2026 · latest 28 Jul 2026
◆ Related on Wire
◆ Topics