Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-20929 allows attackers who can manipulate DNS records to relay Kerberos authentication to Active Directory Certificate Services, bypassing environments where NTLM has been disabled as a relay defense. Successful exploitation produces attacker-controlled certificates valid for a year or more, granting persistent, credential-independent access to Windows infrastructure. Microsoft patched this in January 2026; unpatched Active Directory environments with AD CS Web Enrollment enabled are at elevated risk of durable, difficult-to-detect compromise.

Author

Tech Jacks Solutions