Feed/CVE-2026-54121
CVE-2026-54121HIGHCVSS 8.8

CVE-2026-54121

Published Jul 14, 2026·Updated Jul 21, 2026

NVD Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Public Exploits & PoCs11 found

[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121

Certighost POC

6

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-54121-CertiGhost

CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

1

[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121

CVE-2026-54121

1

[POC] GHSA-8gj2-2cvc-6xx7 — Certighost-CVE-2026-54121

Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.

[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121

CVE-2026-54121 - Draft

[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121-PoC-Exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework ⚡Weaponized tool with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒

[POC] GHSA-3whf-vgf2-9w6g — Metasploit-CVE-2026-54121-Certighost

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.

[POC] GHSA-6vch-q96h-7gc3 — certighost-cve-2026-54121-slides

Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.

PoC: certighost

fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121

PoC: CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

PoC: CVE-2026-54121-CertiGhost

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free