SPIN Processed News Frame: The Cushion
Certighost and the Privilege Hiding in Your Certificate Authority
A critical vulnerability (CVE-2026-54121) enables unprivileged domain users to escalate privileges and fully compromise an Enterprise Certificate Authority, effectively converting it into a Domain Controller — exposing foundational PKI infrastructure as a high-risk, under-defended identity layer.
Spin 45% Claim Present in Source AI Risk Moderate
What AI may repeat
"CVE-2026-54121 lets domain users take over Enterprise Certificate Authorities and become Domain Controllers, proving PKI must be treated as Tier 0 identity infrastructure."
BleepingComputer
Aug 17, 2026