ZeroHour

CVE-2026-69624

mass

Authenticated Input-Validation Tampering Flaw in Microsoft AD CS

CVSS 3.1
6.5 medium
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69624 is an incomplete list of disallowed inputs (CWE-184) in Microsoft Active Directory Certificate Services (AD CS), the Windows Server role that issues and manages digital certificates for Active Directory environments. A network-based attacker who already holds a valid low-privileged (authorized) account can send crafted input that bypasses the flawed disallow list, with no user interaction required. The impact is confined to integrity (CVSS: no confidentiality loss, no availability loss, high integrity impact), meaning the attacker can tamper with certificate-services state or data rather than read secrets or disrupt the service. Any organization running the AD CS role on Windows Server is potentially affected, though exploitation requires authenticated access rather than anonymous internet reachability. As of the September 2026 Patch Tuesday release — which fixed 966 flaws including 2 zero-days — there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.7% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to every Windows Server hosting the AD CS role, prioritizing root and issuing CAs. In the interim, review and restrict certificate-enrollment and template permissions for low-privileged accounts, since exploitation requires authenticated access, and monitor CA logs for unexpected certificate or configuration changes. Confirm post-patch that certificate issuance and template settings are intact, given the tampering-only impact.

Affected
Microsoft Active Directory Certificate Services (AD CS) role on Windows Server
Estimated exposure
masswell over 100,000 AD CS certificate-authority server instances worldwide (exact count unknown) — AD CS ships as a Windows Server role and is deployed by the majority of enterprise Active Directory environments, each typically operating at least one CA server, implying more than 100,000 instances globally; note that attack exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

Weakness
CWE-184
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1