← back

CVE-2026-54121

HIGH · 8.8 EPSS 1.1%
hype LIKELY HACK · 78 hack

Public PoC, Microsoft patches released, defender alerts live, but not yet KEV-listed; lab exploitation confirmed.

What: Improper authorization in Active Directory Certificate Services (AD CS) allowing authenticated attackers to elevate privileges and potentially compromise Windows domains; CVSS 8.8 (HIGH).

Why it matters: Public PoC released 24 July 2026 by H0j3n and Aniq F; Microsoft patched on 14 July; Microsoft Defender already detecting exploitation attempts (malicious certificate requests). Social signal shows working exploitation in lab environments and active defender alerting—not theoretical.

Where it's seen: PoC posted to GitHub gist; security news outlets (HelpNetSecurity) covering; defenders reporting successful lab reproduction; Microsoft Defender generating detection alerts for AD CS abuse; domain-takeover impact framing driving urgency.

RISK: CRITICAL — Authenticated network privilege escalation in critical identity infrastructure (AD CS); PoC public; defender detections active.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/28/2026, 1:43:08 AM

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected versions

  • microsoft/windows_10_1607
    • < 10.0.14393.9339
  • microsoft/windows_10_1809
    • < 10.0.17763.9020
  • microsoft/windows_server_2012
    • r2
  • microsoft/windows_server_2016
    • < 10.0.14393.9339
  • microsoft/windows_server_2019
    • < 10.0.17763.9020
  • microsoft/windows_server_2022
    • < 10.0.20348.5386
  • microsoft/windows_server_2025
    • < 10.0.26100.33158

Weaknesses

Vendors

  • microsoft

Products

  • windows_10_1607
  • windows_10_1809
  • windows_server_2012
  • windows_server_2016
  • windows_server_2019
  • windows_server_2022
  • windows_server_2025