TECH NEWS
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
Microsoft has patched a high-severity vulnerability in Active Directory Certificate Services that allowed a user with basic domain access to obtain a valid certificate identifying them as a Domain Controller. Tracked as CVE-2026-54121 and named Certighost, the flaw received a CVSS score of 8.8. Researchers H0j3n and Aniq Fakhrul