CVE-2026-54121
HIGH · 8.8 EPSS 1.1%Public PoC, Microsoft patches released, defender alerts live, but not yet KEV-listed; lab exploitation confirmed.
What: Improper authorization in Active Directory Certificate Services (AD CS) allowing authenticated attackers to elevate privileges and potentially compromise Windows domains; CVSS 8.8 (HIGH).
Why it matters: Public PoC released 24 July 2026 by H0j3n and Aniq F; Microsoft patched on 14 July; Microsoft Defender already detecting exploitation attempts (malicious certificate requests). Social signal shows working exploitation in lab environments and active defender alerting—not theoretical.
Where it's seen: PoC posted to GitHub gist; security news outlets (HelpNetSecurity) covering; defenders reporting successful lab reproduction; Microsoft Defender generating detection alerts for AD CS abuse; domain-takeover impact framing driving urgency.
RISK: CRITICAL — Authenticated network privilege escalation in critical identity infrastructure (AD CS); PoC public; defender detections active.
Description
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Affected versions
- microsoft/windows_10_1607
- < 10.0.14393.9339
- microsoft/windows_10_1809
- < 10.0.17763.9020
- microsoft/windows_server_2012
- r2
- microsoft/windows_server_2016
- < 10.0.14393.9339
- microsoft/windows_server_2019
- < 10.0.17763.9020
- microsoft/windows_server_2022
- < 10.0.20348.5386
- microsoft/windows_server_2025
- < 10.0.26100.33158
Weaknesses
Vendors
- microsoft
Products
- windows_10_1607
- windows_10_1809
- windows_server_2012
- windows_server_2016
- windows_server_2019
- windows_server_2022
- windows_server_2025