Established 2026Friday, 21 August 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 (Certighost) lets a standard domain user escalate to Domain Controller via Enterprise CA abuse—a stark reminder to treat PKI as Tier 0 identity infrastructure.

Summary written by editorial AI · Source link below

Filed by BleepingComputer1 min readCVE-2026-54121Read at source ↗
CVSS8.8highCVE-2026-54121

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]

Editorial Analysis

Why it matters

Standing privileges and implicit trust in Enterprise CAs create a privilege-escalation path from any domain user to full domain compromise—a systemic risk in most Active Directory environments.

What to do

Patch CVE-2026-54121 immediately, audit Enterprise CA permissions and certificate templates, and reclassify PKI as Tier 0 infrastructure with corresponding hardening.

Board brief

A single vulnerability in your certificate authority can hand any employee Domain Controller privileges—PKI hardening is now a board-level priority.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at BleepingComputer

External link — opens at BleepingComputer in a new tab.

§
Continue with

More from the Vulnerabilities Desk