Semperis researchers discover Active Directory flaws


By Dylan Bushell-Embling
Thursday, 27 August, 2026

Semperis researchers discover Active Directory flaws

Security researchers at cyber resilience company Semperis have uncovered two new Active Directory vulnerabilities capable of giving attackers a foothold for full domain compromise.

The privilege escalation vulnerabilities can potentially be exploited to allow threat actors to move laterally, establish persistence, weaken authentication, steal sensitive data, disrupt critical services and potentially deploy ransomware across the organisation, Semperis said. As a worst case scenario, the vulnerabilities could lead to full domain takeover.

The vulnerabilities take advantage of hidden Unicode characters and weaknesses in Active Directory name validation on unpatched versions of the Microsoft directory service.

Microsoft patched one of the vulnerabilities in March and the other in April. The company rated the vulnerabilities as important elevation of privilege vulnerabilities, while Semperis has rated both as being of severe risk to organisations.

Named ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), these Active Directory vulnerabilities could allow attackers to manipulate how an organisation’s identity system recognises users and services.

Semperis security researcher Shai Laron, who discovered the two vulnerabilities, said the potential attack would involve creating two accounts or services that appear to have the same name, and exploiting the resulting confusion to disrupt access to business-critical systems or impersonate highly privileged users.

Active Directory is routinely targeted as part of malicious activity on Australian enterprise networks. The Australian Signals Directorate (ASD) warns it is susceptible to compromise partially because every user in Active Directory has sufficient permission to enable them to both identify and exploit weaknesses. It has specifically highlighted the use of compromised accounts to establish admin-level access and move laterally in successful breaches of Australian organisations.

“Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges,” Laron said. “This level of privilege effectively grants full control over an organisation’s environment. Identity protection therefore plays an integral part in enterprise security, and organisations invest great efforts in preventing threat actors from gaining access to administrators’ credentials.”

More information is available here.

Image credit: iStock.com/JuSun

Related News

Fortinet buys Virtue AI to bolster AI security portfolio

Fortinet has acquired AI runtime protection and automated AI validation company Virtue AI to...

Fujitsu and DigiCert to automate digital certificate renewals

A new partnership aims to help navigate escalating operational and security risks by automating...

ASD says beware of AI agents taking unexpected actions

Recent reported cyber incidents highlight the goal misalignment and unintended behaviour risks...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd