Overview
- Researchers who reported CVE-2026-54121 have published a working proof-of-concept that automates a chase-based attack against Active Directory Certificate Services.
- Microsoft issued fixes for the flaw in its July 14, 2026 security updates that add checks to verify chase hostnames and SIDs before the CA follows a requester-supplied chase target.
- The vulnerability lets any authenticated domain user with network access request a CA-signed machine certificate that can authenticate as a target machine or Domain Controller via PKINIT.
- With a forged DC certificate an attacker can obtain Kerberos credentials, run a DCSync to extract the krbtgt secret, and escalate a low-privilege account to full domain compromise.
- Administrators should install the July 14 updates on every issuing AD CS server as a priority; if immediate patching is not possible, the optional chase fallback can be disabled via the documented registry/policy change as a temporary mitigation.