Wire · technology
Proof-of-concept exploit released for Certighost Windows AD CS vulnerability
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 28 July 2026 · Fusion42 review
A proof-of-concept exploit for CVE-2026-54121 (Certighost) in Windows Active Directory Certificate Services has been released, allowing authenticated attackers to impersonate domain controllers and compromise entire Windows domains. Microsoft patched the vulnerability in July 2026 by adding validation to the certificate authority's chase process.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
Your entire customer base running Windows domains is now at active risk: the exploit automating domain takeover is public, and the window between now and full patch deployment across enterprises is your moment to sell detection or response tools. Enterprise security teams will spend the next 90 days in emergency mode—your IR and visibility products become non-negotiable.
◆ Related on Wire
◆ Topics