PoC Archive PoC Archive

tag

Active-Directory

Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912 network Unverified
CVE-2026-27912networkHIGH 8Unverified2026-08-11Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 network Patched
CVE-2026-25177networkHIGH 8.8Patched2026-08-11AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CVE-2026-54121 network Patched
CVE-2026-54121networkHIGH 8.8Patched2026-07-27Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128 network Unverified
CVE-2026-26128networkCRITICALUnverified2026-07-05VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085) KEV RW EPSS 27%
CVE-2024-37085 network Patched
CVE-2024-37085networkMEDIUM 6.8Patched2026-05-16