Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2982 articles · 185103 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-54121PATCHED
microsoft · windows_10_1607

Active Directory Certificate Services Elevation of Privilege Vulnerability

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Affected Products

VendorProductVersions
microsoftwindows_10_160710.0.14393.0, 10.0.17763.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows_10_1809cve_cpe95%
microsoftwindows_server_2012cve_cpe95%
microsoftwindows_server_2016cve_cpe95%
microsoftwindows_server_2019cve_cpe95%
microsoftwindows_server_2022cve_cpe95%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121(vendor-advisory, patch)

Related News (10 articles)

Tier B
CERT-FR6d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier D
Help Net Security6d ago
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
→ No new info (linked only)
Tier D
Heise Security11d ago
Microsoft: Proof-of-Concept-Exploit für „Certighost“-AD-Lücke aufgetaucht
→ No new info (linked only)
Tier D
BleepingComputer12d ago
New Certighost PoC exploit lets attackers hijack Windows domains
→ No new info (linked only)
Tier D
The Hacker News12d ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
→ No new info (linked only)
Tier D
Help Net Security12d ago
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
→ No new info (linked only)
Tier D
The Hacker News15d ago
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
→ No new info (linked only)
Tier B
CERT-FR25d ago
Multiples vulnérabilités dans Microsoft Windows (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB25d ago
CVE-2026-54121 | Microsoft Windows up to Server 2025 Active Directory Certificate Services improper authorization
→ No new info (linked only)
Tier C
Qualys Blog25d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121
CWECWE-285
PublishedJul 14, 2026
Last enriched25d agov2
Trending Score32
Source articles10
Independent7
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 128
MEDIUMCVE-2026-56164EXPKEV
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Trending: 127
HIGHCVE-2026-42897EXPKEV
Microsoft Exchange Server Spoofing Vulnerability
Trending: 71
CRITICALCVE-2026-65667
Microsoft Teams Elevation of Privilege Vulnerability
Trending: 51
CRITICALCVE-2026-56162
Azure SQL Database Elevation of Privilege Vulnerability
Trending: 51

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: vendor, product, affectedVersions
Jul 14, 2026
Patch Available
Jul 26, 2026

Version History

v2
Last enriched 25d ago
v2Tier C25d ago

Updated vendor to Microsoft, product to Windows Server, affected versions to 'up to Server 2025', severity to CRITICAL, and noted that no exploit is available.

vendorproductaffectedVersions
via VulDB
v125d ago

Initial creation