Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3807 articles · 197767 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-54121PATCHED
microsoft · windows_10_1607

Active Directory Certificate Services Elevation of Privilege Vulnerability

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Affected Products

VendorProductVersions
microsoftwindows_10_160710.0.14393.0, 10.0.17763.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows_10_1809cve_cpe95%
microsoftwindows_server_2012cve_cpe95%
microsoftwindows_server_2016cve_cpe95%
microsoftwindows_server_2019cve_cpe95%
microsoftwindows_server_2022cve_cpe95%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121(vendor-advisory, patch)

Related News (10 articles)

Tier B
CERT-FR23d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier D
Help Net Security24d ago
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
→ No new info (linked only)
Tier D
Heise Security29d ago
Microsoft: Proof-of-Concept-Exploit für „Certighost“-AD-Lücke aufgetaucht
→ No new info (linked only)
Tier D
BleepingComputer29d ago
New Certighost PoC exploit lets attackers hijack Windows domains
→ No new info (linked only)
Tier D
The Hacker News30d ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
→ No new info (linked only)
Tier D
Help Net Security30d ago
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
→ No new info (linked only)
Tier D
The Hacker News33d ago
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
→ No new info (linked only)
Tier B
CERT-FR42d ago
Multiples vulnérabilités dans Microsoft Windows (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB42d ago
CVE-2026-54121 | Microsoft Windows up to Server 2025 Active Directory Certificate Services improper authorization
→ No new info (linked only)
Tier C
Qualys Blog42d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121
CWECWE-285
PublishedJul 14, 2026
Last enriched42d agov2
Trending Score5
Source articles10
Independent7
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 171
HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 135
CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 89
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 81
HIGHCVE-2026-69414
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 57

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: vendor, product, affectedVersions
Jul 14, 2026
Patch Available
Aug 18, 2026

Version History

v2
Last enriched 42d ago
v2Tier C42d ago

Updated vendor to Microsoft, product to Windows Server, affected versions to 'up to Server 2025', severity to CRITICAL, and noted that no exploit is available.

vendorproductaffectedVersions
via VulDB
v142d ago

Initial creation