# Your Certificate Authority Is a Domain Controller. CVE-2026-54121 Just Made That Undeniable.
The scenario is clean and brutal: a standard domain user — no special rights, no administrative group membership, no reason to be flagged — submits a certificate request to the Enterprise CA and walks away with privileges equivalent to a Domain Controller. No lateral movement required. No credential dumping. No waiting for a privileged user to log into the wrong machine. CVE-2026-54121, now being called Certighost, turns your PKI into the most dangerous unlocked door in the building.
The patch dropped this month. Apply it. But stop there and you will have fixed a line of code while leaving the real vulnerability intact.
## The Mechanism Behind Certighost
ADCS — Active Directory Certificate Services — has been a Tier 0 attack surface hiding in plain sight since at least 2021, when SpecterOps researchers Will Schroeder and Lee Christensen published "Certified Pre-Owned" and documented a taxonomy of Enterprise CA abuses that most organizations had never audited. That research introduced ESC1 through ESC8: ways to abuse misconfigured certificate templates, NTLM relay against the CA's web enrollment interface, and enrollment agent chains to impersonate any principal in the domain — including Domain Controllers.
Certighost is the latest entry in that lineage. CVE-2026-54121 exploits a flaw in how the Enterprise CA processes a specific certificate attribute during enrollment, allowing a low-privileged requester to have the resulting certificate treated as if it were issued to a machine account with DC-equivalent trust. The Kerberos stack sees a valid certificate from a trusted CA. It does not ask further questions.
The vulnerability is real and the proof-of-concept abuse paths are not theoretical. On an unpatched server, the exploit chain from standard domain user to golden ticket in under two minutes is achievable.
## Why the Certificate Authority Has Always Been Tier 0
Here is the thing organizations keep discovering the hard way: control over a CA that can issue certificates for domain authentication *is* Domain Controller equivalence. Always was. The cert issued to a DC that Kerberos trusts for PKINIT authentication is only as trustworthy as the CA that signed it. Compromise the CA — or abuse it — and you can mint your own.
The Active Directory tiering model has been the dominant framework for privilege segmentation in enterprise Windows environments for over a decade. Tier 0 means Domain Controllers, the domain itself, and anything that directly controls them. For years, organizations correctly placed DCs in Tier 0 while leaving the Enterprise CA in some nebulous administrative category managed by the networking team or, worse, accessible by server admins who are explicitly excluded from DC management. This is the same logic gap that made PrintNightmare so devastating: a component that looked like infrastructure plumbing turned out to carry Domain Admin-equivalent blast radius.
Certighost forces this conversation. Again. And it is unlikely to be the last time.
## The Gaps the Patch Cannot Close
Applying the CVE-2026-54121 fix closes the specific attribute-processing flaw. What it does not close is the broader category of risk that makes these vulnerabilities so exploitable when they emerge.
Standing privilege in PKI administration remains the dominant problem. In many enterprise environments, CA administrators are not Tier 0-managed accounts. They are not subject to the same PAW requirements, the same monitoring, or the same access controls applied to Domain Admins. This is misconfigured by design in the sense that organizations built it this way deliberately — they just never modeled the threat.
Certificate template permissiveness is almost always worse than defenders expect when they first audit it. Templates that allow Subject Alternative Name specification by the requester, templates with EKUs that include Client Authentication and Smart Card Logon, enrollment rights granted to broad groups like "Domain Users" or "Authenticated Users" — these configurations exist in production environments right now, unrelated to Certighost, exploitable with tools like Certipy that have been publicly available for three years.
CA audit logging is frequently disabled or never reviewed. The event IDs that would catch Certighost exploitation — 4886, 4887, 4870 — are either not forwarded to SIEM or not alerted on. The first signal of compromise is often a Kerberos anomaly or a DCSync, not a certificate issuance event.
## What Defenders Need to Do This Week
Patch is step one. These are steps two through six:
certipy find -u <user> -p <pass> -target <domain> will surface ESC misconfigurations your PKI team does not know exist. Most organizations that run this for the first time find at least one critical finding.## HackWire Analysis
Certighost lands in a moment when the PKI attack surface is no longer obscure knowledge. The original SpecterOps research in 2021 was the kind of publication that circulated among red teamers for years before it became common board-level vocabulary. That gap is closing. ADCS attacks appear routinely in ransomware intrusion timelines, in APT attribution reports, and in penetration test findings at organizations across every vertical.
What strikes me about CVE-2026-54121 is not the specific flaw — it is what it exposes about the persistence of implicit trust in enterprise architecture. The CA is trusted because it has always been trusted. Nobody went back to model the threat when the attack surface expanded. PKI teams built and maintained CA infrastructure from an availability and reliability perspective, not a security one. And so you have environments where a CA Administrator's credentials receive fewer controls than a SharePoint site owner's.
The phrase "standing privilege" in the advisory is the tell. This is not a zero-day that strikes from nowhere. It is a vulnerability that requires an attacker to have the opportunity to exploit it — and that opportunity exists because organizations maintain permanently-granted, poorly-monitored rights on infrastructure that, if you squint at it correctly, looks exactly like the most powerful server in the domain.
The vendors who sell PAM solutions have been making this argument for years. Certighost is the argument made for them, more concisely, in one CVE. There are defenders who will patch and move on. There are defenders who will treat this as the forcing function to finally model CA privilege as Tier 0. The second group will be significantly harder to compromise in the next three years.
The patch is the easy part. It always was.
— HackWire Editorial
---
## Related Coverage