• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-54121: privilege escalation in Microsoft Windows 10 Version 1607

An authorized attacker can elevate privileges on Windows systems that use Active Directory Certificate Services (AD CS). CVE-2026-54121 is an improper-authorization flaw (CWE-285) that affects multiple Windows branches including Windows 10 Version 1607, Version 1809 and Windows Server 2012/2012 R2/2016/2019; affected builds run from the listed initial builds up to but not including the fixed builds. An attacker needs network access and an authorized account to exploit the vulnerability.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00778
CWE
CWE-285
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high priority — public exploit code exists for CVE-2026-54121, so install the vendor updates or mitigations immediately to reduce risk.

What is CVE-2026-54121?

An authorized attacker can elevate privileges on Windows systems that use Active Directory Certificate Services (AD CS). CVE-2026-54121 is an improper-authorization flaw (CWE-285) that affects multiple Windows branches including Windows 10 Version 1607, Version 1809 and Windows Server 2012/2012 R2/2016/2019; affected builds run from the listed initial builds up to but not including the fixed builds. An attacker needs network access and an authorized account to exploit the vulnerability.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020

Is CVE-2026-54121 being exploited?

Public exploit code is available.

How to fix CVE-2026-54121

  1. Install Microsoft updates that upgrade affected branches to the fixed builds (for example 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, 6.3.9600.23291).
  2. Apply vendor guidance and security updates for Active Directory Certificate Services across affected servers and Server Core installations.
  3. Restrict network exposure of AD CS servers and limit accounts that can interact with certificate services until patches are applied.
  4. Monitor certificate services and authentication logs for unusual privilege changes or certificate operations.

Frequently asked questions

Is CVE-2026-54121 being actively exploited?

Public exploit code is available for CVE-2026-54121.

Which Windows 10 Version 1607 versions are affected by CVE-2026-54121?

Windows 10 Version 1607 and related branches are affected from builds starting at 10.0.14393.0 up to but not including the fixed build 10.0.14393.9339; other affected branches include Windows 10 Version 1809 and several Windows Server releases listed in vendor advisories.

Is there a patch for CVE-2026-54121?

Yes. Microsoft published fixes; affected branches were updated to fixed builds such as 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, and 6.3.9600.23291—apply the corresponding updates for your branch.

Does CVE-2026-54121 require authentication?

Yes. The flaw involves improper authorization in AD CS and requires an authorized attacker account to perform privilege elevation.

References