# KerberLoss: invisible Unicode lets an attacker twin a Kerberos SPN

Source: https://startwithidentity.com/blog/2026-08-13-kerberloss-invisible-unicode-spn/
Last updated: 2026-08-13
License: content by Start with Identity. Cite the source URL.

---

[CVE-2026-25177](https://startwithidentity.com/cves/cve-2026-25177/) is the Active Directory SPN uniqueness bypass Semperis and Shai Laron named KerberLoss. AD did not treat invisible-Unicode look-alikes as collisions, so an attacker who can write an SPN registers a twin of `HTTP/app.contoso.com`, intercepts Kerberos traffic, and can downgrade the client to NTLM. CVSS 8.8. Microsoft patched it in March 2026.

This sits next to the 2025 [Ghost SPN / SMB reflection](https://startwithidentity.com/cves/cve-2025-58726/) work. SPNs are identity, not inventory trivia. We filed the brief under [Kerberos / Active Directory](https://startwithidentity.com/cves/kerberos-ad/) with a concrete hunt: new SPNs that contain non-ASCII characters. There is almost never a business reason.

## Why it matters

SPN uniqueness is the only thing standing between "I can write a servicePrincipalName" and "I am the app." If your delegation graph or DNS self-registration is messy, this CVE is how that mess becomes a ticket.

If you have not confirmed the March 2026 AD updates on every DC, do that, then restrict validated write to servicePrincipalName. The [KerberLoss brief](https://startwithidentity.com/cves/cve-2026-25177/) has the detection notes.

Source: [NVD: CVE-2026-25177](https://nvd.nist.gov/vuln/detail/CVE-2026-25177)
