A proof-of-concept exploit for the "Certighost" vulnerability (CVE-2026-54121) has been released, affecting Windows Active Directory Certificate Services. This vulnerability allows authenticated attackers to compromise a Windows domain by manipulating machine account attributes to obtain certificates from AD CS, enabling them to authenticate as that machine or even as a domain controller. The flaw was reported to Microsoft on May 14, 2026, and addressed in the July 2026 Patch Tuesday updates. The vulnerability exploits a fallback mechanism in AD CS during certificate enrollment requests, allowing attackers to direct the Certification Authority to their controlled systems. The researchers demonstrated that a low-privileged user could create a machine account and use it to impersonate a domain controller, leading to potential domain compromise. Microsoft has added validation to the chase process in the July updates to prevent this exploitation. For those unable to install the updates, a temporary workaround involves disabling the chase fallback, though this has not been extensively tested.