BleepingComputer reports that Certighost, tracked as CVE-2026-54121, exposes a high-impact privilege escalation path in Microsoft Active Directory Certificate Services. According to the report, Microsoft shipped a fix on July 14, 2026, rated the flaw 8.8 on the CVSS scale, and researchers published a working proof-of-concept on July 24. The vulnerability matters because it sits inside an Enterprise Certification Authority, a system that Active Directory environments already trust to issue identity-bearing certificates. BleepingComputer describes the issue as a boundary failure: a standard domain user should not be able to obtain a certificate representing a Domain Controller, but the reported attack chain allows that outcome without changing access control lists. The flaw is tied to an AD CS enrollment behavior called “chase” functionality. When an Enterprise CA cannot immediately resolve a target object locally, BleepingComputer says it can follow requester-supplied routing information through a parameter called cdc to look the object up elsewhere. The reported defect is that the CA does not verify that the cdc endpoint is a legitimate Domain Controller before connecting to it. An attacker can point that parameter at a machine they control, have the rogue endpoint return forged identity data, and cause the CA to bind Domain Controller identity attributes into a signed X.509 certificate. From there, the escalation path uses existing Windows authentication mechanics. BleepingComputer reports that the attacker can use the certificate with PKINIT, the public key extension to Kerberos, to obtain a Ticket Granting Ticket as the Domain Controller’s machine account. That machine-account identity is powerful because Domain Controller accounts have directory replication rights. According to BleepingComputer, those rights are enough to run a DCSync operation against a real Domain Controller and retrieve credential material, potentially including the krbtgt account hash used at the core of Kerberos ticketing. The report says a standard Domain User account was sufficient in testing because default Active Directory settings, including the default MachineAccountQuota that allows ordinary users to create machine accounts, supplied what the chain needed. BleepingComputer also reports that, as of public disclosure, there was no confirmed exploitation in the wild. The risk profile changes, however, once a functional proof-of-concept is public: defenders should treat patched status and CA configuration as urgent verification items, not as routine certificate-services hygiene. Who benefits: Defenders benefit from a clear patch and audit target: Enterprise CAs running AD CS and the enrollment paths around chase functionality. Attackers benefit from any environment that remains unpatched or leaves default AD settings aligned with the reported chain. Who's exposed: Organizations running Microsoft AD CS Enterprise CAs are the exposed population described by the report. The most sensitive cases are environments where low-privileged domain users can still reach the CA enrollment path and default Active Directory settings remain in place.