Start with Identity
Protocol · 13 briefs

Kerberos and Active Directory identity CVEs

PAC validation, PKINIT, S4U, SPN uniqueness, and kpasswd. 2024-2026 made AD's name and ticket story look as fragile as SAML's signature story.

How this protocol fails

A KDC bug is domain identity, not a workstation ticket. The train runs from Kerberos server impersonation and PAC spoofing (2024), through PKINIT/NTAuth and CheckSum S4U (2025), to KerberLoss invisible-Unicode SPNs and ResetNightmare kpasswd (2026). AD CS (Certifried, ESC15) is how a wrong certificate becomes a TGT. Ghost SPNs and DNS self-registration keep reflection alive after the first patch. If you only patch "the CVE on the Patch Tuesday slide" and skip enforcement mode, you are not done.

What security people should do

  • Treat DC Kerberos updates as one train. April 2024 PAC, April 2025 PKINIT, and the 2026 SPN/kpasswd fixes all belong on every DC.
  • Turn on strong certificate mapping (KB5014754) in enforcement, not compatibility. Audit NTAuth. Review ESC1-ESC16 templates.
  • Alert on non-ASCII SPNs and unexpected servicePrincipalName writes. Restrict who can write SPNs and UPNs on privileged accounts.
  • Inventory S4U and constrained delegation. Remove it where a modern path will do.
  • Patch both sides of every forest trust before you flip PAC enforcement.

CVEs in this category

13
Kerberos / Active Directory
0
On CISA KEV
0
Actively exploited
13
Showing
Severity
Year
Status

Showing 13 of 13

Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.