Tag: certificate authorities
1 article

Certighost Exposes Hidden Privilege Risks in Certificate Authorities
A single misstep in a Certificate Authority can have devastating consequences, as seen in CVE-2026-54121, aka Certighost, which allows a low-privileged domain user to escalate to full domain compromise. This shocking vulnerability exploits a little-known "chase" functionality in Active Directory Certificate Services.