The vulnerabilities, tracked as CVE-2026-27912 and CVE-2026-25177, force identity systems to misinterpret usernames and service names. This confusion enables unauthorized actors to disrupt critical services, force weaker authentication protocols, or mask their identity as that of a high-level administrator. While Microsoft issued patches for KerberLoss in March and ResetNightmare in April 2026, the potential for exploitation remains a significant concern for firms relying on legacy identity configurations.
New Active Directory Flaws Expose Enterprises to Full Domain Takeover
Security researcher Shai Laron has uncovered two critical vulnerabilities, dubbed ResetNightmare and KerberLoss, that manipulate Active Directory identity systems. By exploiting hidden Unicode characters and name validation weaknesses, these flaws allow attackers to impersonate privileged users, potentially granting them total control over an organization’s entire digital infrastructure.

ResetNightmare poses the greater threat, as it provides a pathway for low-privileged attackers to escalate their access to full domain dominance. Semperis researchers, who presented these findings at the 2026 Black Hat and DEF CON conferences, emphasize that identity systems often act as the "crown jewel" for cybercriminals. Rather than relying on stolen credentials, these exploits subvert the very logic the system uses to verify access. Security teams are urged to monitor for suspicious directory changes using tools like Security Event ID 5136 to ensure their environments have not been compromised.




Comments (0)
No comments yet. Be the first!