Back to the feed

~/article/certighost-and-the-privilege-hiding-in-your-certificate-authority-u609fn
mediumSource: BleepingComputer

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.

Read at the source

Summary written for cymesh.dev. The full article lives at BleepingComputer.

Referenced CVEs

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/certighost-and-the-privilege-hiding-in-your-certificate-authority-u609fn