Wire · regulatory
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 24 July 2026 · Fusion42 review
Researchers published a working exploit (Certighost) on 24 July that allows low-privileged Active Directory users to impersonate a Domain Controller by obtaining a forged certificate, enabling credential theft via DCSync; Microsoft patched the underlying AD CS flaw (CVE-2026-54121, CVSS 8.8) ten days earlier.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Identity & Access, and 3 sources have reported it between 24 Jul 2026 and 28 Jul 2026.
◆ ◆ The Wire takeaway
If you sell identity management or IAM tooling into enterprises, your customer base just got a 10-day window between patch release and public exploit—and many haven't patched yet. That's a sales signal and a retention risk: call your AD-heavy accounts and find out who's still on pre-July builds.
◆ Coverage
3 sources · first reported 24 Jul 2026 · latest 28 Jul 2026
◆ Related on Wire
◆ Topics