Semperis Researcher Discovers Critical Active Directory Privilege Escalation Flaws
Semperis(opens in new tab)(opens in new tab), the identity-driven cyber resilience and crisis response company, today announced that Shai Laron, Semperis Security Researcher, discovered two critical Active Directory (AD) privilege escalation vulnerabilities(opens in new tab) that could give threat actors a foothold for full domain compromise—enabling them to move laterally, establish persistence, weaken authentication, disrupt critical services, steal sensitive data, and potentially deploy ransomware across the organization. Laron recently presented his findings before large crowds at the 2026 Black Hat and DEF CON conferences.
Also Read: IT Tech Pulse Exclusive Interview with Syed Ali Founder and Chief Executive Officer of EZO
Named ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), these Active Directory vulnerabilities could allow attackers to manipulate how an organization’s identity system recognizes users and services. The vulnerabilities take advantage of hidden Unicode characters and weaknesses in Active Directory name validation. Microsoft patched KerberLoss(opens in new tab) in March 2026 and ResetNightmare in April 2026. Organizations can also use Active Directory auditing, including Security Event ID 5136, to identify suspicious directory changes.
Put simply, attackers could make two different accounts or services appear to have the same name. This identity confusion could disrupt access to business-critical systems, force some services to use a weaker authentication method, or help an attacker impersonate a highly privileged user. ResetNightmare is the more serious of the two vulnerabilities because, under certain conditions, it could enable a low-privileged attacker to take control of an entire Active Directory domain.
“Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges,” said Laron. “This level of privilege effectively grants full control over an organization’s environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in preventing threat actors from gaining access to administrators’ credentials.”
“Shai’s exceptional discovery of the ResetNightmare and KerberLoss Active Directory vulnerabilities reveal how subtle identity confusion in AD can lead to authentication downgrade, denial-of-service, and even full domain takeover,” said Tomer Bar(opens in new tab), Semperis AVP of Security Research. “His work gives defenders critical insight into emerging identity threats and helps organizations strengthen their environments before attackers can exploit them.”
Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA
Microsoft rated the ResetNightmare and KerberLoss vulnerabilities as Important Elevation of Privilege vulnerabilities in its severity-label system. Semperis rates both vulnerabilities as a SEVERE risk to organizations.
Laron’s research underscores the importance of treating identity systems as a critical security boundary. Attackers do not always need to steal an administrator’s password if they can manipulate the systems that decide who is allowed to access critical resources.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.