Identity & AccessPress Release

Semperis Researcher Discovers Critical Active Directory Privilege Escalation Vulnerabilities

ResetNightmare and KerberLoss Exploit Weaknesses in How Identity Systems Interpret Usernames and Service Names, Potentially Allowing Attackers to Disrupt Services, Weaken Authentication, or Impersonate Privileged Users

Semperis, the identity-driven cyber resilience and crisis response company, has announced that Shai Laron, Semperis Security Researcher, discovered two critical Active Directory (AD) privilege escalation vulnerabilities that could give threat actors a foothold for full domain compromise—enabling them to move laterally, establish persistence, weaken authentication, disrupt critical services, steal sensitive data, and potentially deploy ransomware across the organisation. Laron recently presented his findings before large crowds at the 2026 Black Hat and DEF CON conferences. 

Named ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), these Active Directory vulnerabilities could allow attackers to manipulate how an organisation’s identity system recognises users and services. The vulnerabilities take advantage of hidden Unicode characters and weaknesses in Active Directory name validation. Microsoft patched KerberLoss in March 2026 and ResetNightmare in April 2026. Organizations can also use Active Directory auditing, including Security Event ID 5136, to identify suspicious directory changes.

Put simply, attackers could make two different accounts or services appear to have the same name. This identity confusion could disrupt access to business-critical systems, force some services to use a weaker authentication method, or help an attacker impersonate a highly privileged user. ResetNightmare is the more serious of the two vulnerabilities because, under certain conditions, it could enable a low-privileged attacker to take control of an entire Active Directory domain. 

“Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges,” said Laron. “This level of privilege effectively grants full control over an organization’s environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in preventing threat actors from gaining access to administrators’ credentials.”

Shai’s exceptional discovery of the ResetNightmare and KerberLoss Active Directory vulnerabilities reveal how subtle identity confusion in AD can lead to authentication downgrade, denial-of-service, and even full domain takeover,” said Tomer Bar, Semperis AVP of Security Research. “His work gives defenders critical insight into emerging identity threats and helps organisations strengthen their environments before attackers can exploit them.”

Microsoft rated the ResetNightmare and KerberLoss vulnerabilities as Important Elevation of Privilege vulnerabilities in its severity-label system. Semperis rates both vulnerabilities as a SEVERE risk to organisations.

Laron’s research underscores the importance of treating identity systems as a critical security boundary. Attackers do not always need to steal an administrator’s password if they can manipulate the systems that decide who is allowed to access critical resources.

To learn more, visit: AD Research: Two new vulnerabilities could lead to full domain takeover

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *