Certighost: any user could become your Domain Controller. The question isn't whether you patched, it's whether you've audited your AD CS
Certighost (CVE-2026-54121) let an unprivileged domain user impersonate a Domain Controller via Active Directory Certificate Services and take over the entire domain. Microsoft patched it on July 14; a working PoC has been public since July 24. The mechanism in one sentence, why AD CS is the escalation surface almost nobody audits, and the plan for today: patch, inventory your CAs, machine account quota to zero, and audit templates.