Active Directory Certificate Services (AD CS) Tampering Vulnerability
MonitorCVSS 6.5CVE-2026-69624Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Incomplete validation of user input in Active Directory Certificate Services allows an authorized attacker to tamper with certificate data over the network. This could enable unauthorized certificate issuance or manipulation of certificate attributes that downstream systems rely on for authentication and trust.
What this means
What could happen
An authorized user with access to Active Directory Certificate Services could modify certificate-related data, potentially allowing them to issue unauthorized certificates or manipulate certificate validation processes that critical infrastructure systems may rely on.
Who's at risk
Water utilities and municipal electric operators running Windows Server 2016, 2019, 2022, or 2025 as domain controllers or certificate servers should prioritize this update. Any organization using AD CS for SCADA system authentication or industrial device certificate validation is at risk if an insider or compromised account has elevated AD permissions.
How it could be exploited
An attacker with valid credentials for your Active Directory environment could interact with AD CS APIs or interfaces to submit specially crafted inputs that bypass validation checks, allowing them to tamper with certificate attributes or issuance parameters.
Prerequisites
- Valid Active Directory user credentials or service account access
- Network access to the AD CS server (typically port 443 for web enrollment or RPC ports 135/445 for admin access)
- Administrative or Certificate Manager roles on the AD CS server
Requires valid credentialsLow complexity exploitationAffects identity and trust infrastructurePotential to compromise SCADA/ICS device trust chains
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/6Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 and Server Core to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 and Server Core to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 and Server Core to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 and Server Core to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9512 or later
Long-term hardening
0/2HARDENINGRestrict network access to AD CS servers to only authorized administrative users and systems; disable web enrollment if not required
HARDENINGReview AD CS certificate manager role assignments and revoke unnecessary elevated permissions
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/d8d50545-35c6-4d4c-a7dc-8b5e7589d25fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.