#7
BleepingComputer
general
August 17, 2026 at 14:00 UTC
Certighost and the Privilege Hiding in Your Certificate Authority
By Sponsored by BeyondTrust
AI Summary
CVE-2026-54121, dubbed Certighost, allows a standard domain user to elevate privileges to effectively control an Enterprise Certificate Authority as a Domain Controller, targeting Windows PKI infrastructure as Tier 0 identity assets. The vulnerability highlights the danger of standing privilege and implicit trust in enterprise CA deployments, where PKI systems are often under-hardened relative to their critical role.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →