Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse

2026-04-01T07:23:32Z1e362ffb9349d58ef4f18841f103c009b885645b3fa2e63372b085309bc46617
Active DirectoryAuthentication relayCNAME abuseCVE-2026-20929DNSDelegationDetectionIdentity theftKDCKerberosMitigationRelay attackService Principal Name

What happened

CrowdStrike published detection guidance for CVE-2026-20929, a Kerberos authentication-relay technique that abuses DNS CNAME records to facilitate Kerberos relay/impersonation in Active Directory environments. The advisory focuses on detection and mitigation controls for identifying CNAME-based referral abuse, hardening Kerberos delegation and SPNs, and monitoring related DNS and KDC activity to reduce risk of account impersonation and lateral movement.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
1e362ffb9349d58ef4f18841f103c009b885645b3fa2e63372b085309bc46617
Enrichment time
2026-04-01T07:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.