DIRAS TAKE
Treat this as high priority — public exploit code exists for CVE-2026-54121, so install the vendor updates or mitigations immediately to reduce risk.
What is CVE-2026-54121?
An authorized attacker can elevate privileges on Windows systems that use Active Directory Certificate Services (AD CS). CVE-2026-54121 is an improper-authorization flaw (CWE-285) that affects multiple Windows branches including Windows 10 Version 1607, Version 1809 and Windows Server 2012/2012 R2/2016/2019; affected builds run from the listed initial builds up to but not including the fixed builds. An attacker needs network access and an authorized account to exploit the vulnerability.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
Is CVE-2026-54121 being exploited?
Public exploit code is available.
How to fix CVE-2026-54121
- Install Microsoft updates that upgrade affected branches to the fixed builds (for example 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, 6.3.9600.23291).
- Apply vendor guidance and security updates for Active Directory Certificate Services across affected servers and Server Core installations.
- Restrict network exposure of AD CS servers and limit accounts that can interact with certificate services until patches are applied.
- Monitor certificate services and authentication logs for unusual privilege changes or certificate operations.
Frequently asked questions
Is CVE-2026-54121 being actively exploited?
Public exploit code is available for CVE-2026-54121.
Which Windows 10 Version 1607 versions are affected by CVE-2026-54121?
Windows 10 Version 1607 and related branches are affected from builds starting at 10.0.14393.0 up to but not including the fixed build 10.0.14393.9339; other affected branches include Windows 10 Version 1809 and several Windows Server releases listed in vendor advisories.
Is there a patch for CVE-2026-54121?
Yes. Microsoft published fixes; affected branches were updated to fixed builds such as 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, and 6.3.9600.23291—apply the corresponding updates for your branch.
Does CVE-2026-54121 require authentication?
Yes. The flaw involves improper authorization in AD CS and requires an authorized attacker account to perform privilege elevation.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54121
- cve.org/CVERecord?id=CVE-2026-54121
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026