Mon, 31 Aug 2026

Semperis researchers expose identity confusion bugs in Microsoft AD leading to Kerberos downgrade

Cyber resilience specialist Semperis has disclosed two critical Active Directory (AD) privilege escalation vulnerabilities that could allow threat actors to achieve full domain compromise.

The security flaws enable attackers to move laterally, establish persistence, weaken authentication, disrupt services, exfiltrate data, and deploy ransomware across enterprise networks.

Identity confusion enables Kerberos downgrade and domain takeover

The flaws, designated ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), exploit weaknesses in Active Directory name validation alongside hidden Unicode characters. These flaws allow adversaries to manipulate how directory systems interpret usernames and service names.

By making distinct accounts or services appear identical, attackers can induce identity confusion across enterprise systems:

  • KerberLoss (CVE-2026-25177): Exploits naming validation to force services to revert to weaker authentication mechanisms or disrupt access to business-critical systems.
  • ResetNightmare (CVE-2026-27912): Represents the more severe vulnerability, allowing a low-privileged threat actor under specific conditions to impersonate administrative accounts and take complete control of an Active Directory domain.

Patching timelines and detection measures

Microsoft addressed KerberLoss in its March 2026 security updates and patched ResetNightmare in April 2026. Whilst Microsoft classified both flaws as "Important" Elevation of Privilege vulnerabilities under its severity framework, Semperis rates them as a severe risk to corporate environments.

To detect potential exploitation attempts, security teams can leverage Active Directory auditing, specifically monitoring Security Event ID 5136 to spot unauthorised directory attribute modifications.

Semperis security researcher, Shai Laron emphasised: "Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges.

"This level of privilege effectively grants full control over an organization’s environment. Identity protection therefore plays an integral part in enterprise security, and organisations invest great efforts in preventing threat actors from gaining access to administrators’ credentials." Shai Laron

Tomer Bar, Semperis AVP of Security Research, stated: "Shai’s exceptional discovery of the ResetNightmare and KerberLoss Active Directory vulnerabilities reveal how subtle identity confusion in AD can lead to authentication downgrade, denial-of-service, and even full domain takeover.

Related:  Third-party exploits now primary access vector in Google Cloud attacks

His work gives defenders critical insight into emerging identity threats and helps organizations strengthen their environments before attackers can exploit them."

Related Stories

MORE STORIES