Hello,
Installing the July 14, 2026 update for CVE-2026-54121 (Certighost) will harden your Enterprise CA servers by enforcing strict validation on chase fallback. With EDITF_ENABLECHASECLIENTDC enabled today, the CA may chase client-supplied attributes to arbitrary hosts, which is the core of the vulnerability. After the patch, the CA will only chase to verified Domain Controllers, blocking rogue LDAP endpoints and preventing certificate issuance abuse. The main disadvantage is that if you rely on chase fallback for legitimate workflows, those requests may fail post-update. Most enterprises do not depend on this feature, so the impact is usually minimal. Before installing, review your certificate templates and enrollment policies to confirm no critical process depends on chase fallback. If you cannot patch immediately, disable chase fallback via certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC and restart CertSvc as a temporary mitigation. Given active exploitation and public proof-of-concept code, applying the update is strongly recommended.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
HP.