# KerberLoss, invisible-Unicode SPN uniqueness bypass

Source: https://startwithidentity.com/cves/cve-2026-25177/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Active Directory's SPN uniqueness check did not treat invisible-Unicode look-alikes as collisions. An attacker who can write an SPN registers a twin of `HTTP/app.contoso.com`, intercepts Kerberos traffic, and can downgrade the client to NTLM. Semperis and Shai Laron named it KerberLoss. CVSS 8.8. Microsoft patched in March 2026.

## Why it matters

SPN uniqueness is the only thing standing between "I can write a servicePrincipalName" and "I am the app." Combined with [Ghost SPNs](https://startwithidentity.com/cves/cve-2025-58726/) and [ResetNightmare](https://startwithidentity.com/cves/cve-2026-27912/), 2026 made AD's name-uniqueness story look as fragile as SAML's signature-binding story.

## What to do

- Deploy the March 2026 AD / Kerberos updates on every DC.
- Alert on new SPNs that contain non-ASCII characters. There is almost never a business reason.
- Restrict `Validated write to service principal name` to the smallest set of computer accounts that need it.
- [Semperis](https://startwithidentity.com/vendors/itdr/semperis/) published detection guidance. Use it even after you patch.

## After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

- **Rotate the krbtgt account twice**, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
- **Audit AD CS certificate templates** for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See [certificate lifecycle](https://startwithidentity.com/glossary/certificate-lifecycle/).
- **Review privileged group membership and delegation rights** (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
- **Hunt for tickets with anomalous lifetimes or encryption types**, and for authentications to services that identity never touches.
- **Treat any issued certificate as a durable credential**: revoking a user's password does not revoke a certificate that authenticates as them. See [privilege escalation](https://startwithidentity.com/glossary/privilege-escalation/) and [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2026-25177](https://nvd.nist.gov/vuln/detail/CVE-2026-25177)
- Semperis / Shai Laron, KerberLoss
