A newly released proof-of-concept exploit for "Certighost" demonstrates how authenticated attackers can hijack Windows domains by exploiting a vulnerability in Active Directory Certificate Services (AD CS). Tracked as CVE-2026-54121, the flaw allows low-privileged domain users to impersonate a Domain Controller and gain administrative control over the entire domain.