A proof-of-concept exploit for a vulnerability in Windows Active Directory Certificate Services (AD CS), identified as CVE-2026-54121, has emerged, allowing authenticated attackers to compromise an entire Windows domain. Microsoft addressed this vulnerability in its July 2026 security updates. The flaw enables attackers to manipulate machine account attributes, obtaining certificates to impersonate critical domain controllers and execute privileged Active Directory operations. Researchers H0j3n and Aniq Fakhrul discovered the vulnerability and publicly disclosed it with a functional exploit that exploits a fallback mechanism in AD CS. This exploit can automate the extraction of sensitive credentials through a DCSync attack. Microsoft has since implemented additional validation measures to enhance security against this vulnerability.