Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
2026-07-27T20:51:33Z•21bcff6ed61d857ffb62c0ca6f2cddecf16218af0c47c9471e955097fdca7801
AD CSAI profilingActive Directory Certificate ServicesCertighostDolphin XMicrosoftMicrosoft 365Russian threat actorsZimbracredential theftdomain controller impersonationinformation disclosuremalwarephishingprivilege escalationzero-day
What happened
HackRead reports that Microsoft patched the Certighost vulnerability in its July 2026 security updates. The flaw allowed a low-privilege domain user to obtain a valid Domain Controller certificate through Active Directory Certificate Services (AD CS), enabling domain controller impersonation and potentially domain-wide compromise. The feed also includes reports of hotel Wi-Fi gateway compromises targeting Microsoft 365 credentials and tokens, a Zimbra zero-day used by Russian hackers to steal email and credentials, Dolphin X malware profiling Windows victims, and data-exposure issues involving
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 21bcff6ed61d857ffb62c0ca6f2cddecf16218af0c47c9471e955097fdca7801
- Enrichment time
- 2026-07-27T20:51:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.