Certighost: How to Hunt for the Exploit in AD CS

Certighost (CVE-2026-54121) can turn a trusted CA into part of an attack path when certificate identity validation is compromised. While Microsoft has patched the vulnerability, it will not determine whether your environment was exploited before the fix was installed.
Download Certighost: How to Hunt for the Exploit in Microsoft AD CS to learn how to identify potentially exposed CAs and templates, investigate suspicious certificate activity, and hunt for evidence of the Certighost attack chain.
