CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
- Affected products
- Active Directory Certificate Services, Windows
- Microsoft Windows 10 1607
- < 10.0.14393.9339
- Microsoft Windows 10 1809
- < 10.0.17763.9020
- Microsoft Windows Server 2012
- All versions
- Microsoft Windows Server 2016
- < 10.0.14393.9339
- Microsoft Windows Server 2019
- < 10.0.17763.9020
- Microsoft Windows Server 2022
- < 10.0.20348.5386
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.1% (62th percentile)
- Weakness
- CWE-285
- NVD status
- Analyzed
- Published
- 2026-07-14
CVE-2026-54121 at NVD
12 known exploits for CVE-2026-54121
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
Exploit for Improper Authorization in Microsoft
CVE-2026-54121