Home / Aug 18, 2026 / Story
0
#7 BleepingComputer general August 17, 2026 at 14:00 UTC

Certighost and the Privilege Hiding in Your Certificate Authority

By Sponsored by BeyondTrust

AI Summary

CVE-2026-54121, dubbed Certighost, allows a standard domain user to elevate privileges to effectively control an Enterprise Certificate Authority as a Domain Controller, targeting Windows PKI infrastructure as Tier 0 identity assets. The vulnerability highlights the danger of standing privilege and implicit trust in enterprise CA deployments, where PKI systems are often under-hardened relative to their critical role.

Relevance score: 78.0/100

# More from August 18