Semperis Researcher Discovers Critical Active Directory Privilege Escalation Vulnerabilities
ResetNightmare and KerberLoss exploit weaknesses in how identity systems interpret usernames and service names, potentially allowing attackers to disrupt services, weaken authentication, or impersonate privileged users.
Named ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), these Active Directory vulnerabilities could allow attackers to manipulate how an organization's identity system recognizes users and services. The vulnerabilities take advantage of hidden Unicode characters and weaknesses in Active Directory name validation. Microsoft patched KerberLoss in
Put simply, attackers could make two different accounts or services appear to have the same name. This identity confusion could disrupt access to business-critical systems, force some services to use a weaker authentication method, or help an attacker impersonate a highly privileged user. ResetNightmare is the more serious of the two vulnerabilities because, under certain conditions, it could enable a low-privileged attacker to take control of an entire Active Directory domain.
"Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges," said Laron. "This level of privilege effectively grants full control over an organization's environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in preventing threat actors from gaining access to administrators' credentials."
"Shai's exceptional discovery of the ResetNightmare and KerberLoss Active Directory vulnerabilities reveal how subtle identity confusion in AD can lead to authentication downgrade, denial-of-service, and even full domain takeover," said Tomer Bar, Semperis AVP of Security Research. "His work gives defenders critical insight into emerging identity threats and helps organizations strengthen their environments before attackers can exploit them."
Microsoft rated the ResetNightmare and KerberLoss vulnerabilities as Important Elevation of Privilege vulnerabilities in its severity-label system. Semperis rates both vulnerabilities as a SEVERE risk to organizations.
Laron's research underscores the importance of treating identity systems as a critical security boundary. Attackers do not always need to steal an administrator's password if they can manipulate the systems that decide who is allowed to access critical resources.
To learn more, visit: AD Research: Two new vulnerabilities could lead to full domain takeover
About Semperis
Semperis is the identity-driven cyber resilience and crisis management company trusted by the world's largest enterprises and government agencies to protect critical identity systems. Purpose-built for multi-cloud and hybrid identity environments—including Active Directory, Entra ID, Okta, and Ping Identity—Semperis helps organizations prevent, detect, respond to, and recover from identity-based cyberattacks.
Modern cyberattacks are won or lost at the identity layer, where failures now escalate into full-scale business crises. Semperis' AI-powered platform unifies identity lifecycle defense and crisis management—hardening identity infrastructure, detecting and containing active threats, enabling rapid, trusted recovery, and supporting secure, out-of-band coordination when core systems are disrupted—all reinforced by a world-class identity forensics and incident response team.
As part of its mission to help organizations achieve true cyber resilience, Semperis supports the broader cyber community through the award-winning Hybrid Identity Protection (HIP) Conference and Podcast and free identity security tools including Purple Knight and Forest Druid. More than 1,200 organizations—including over 25% of the 100 largest U.S. companies—rely on Semperis. The company is privately held, headquartered in Hoboken, New Jersey, and serves customers in more than 40 countries.
Learn more: semperis.com
Follow us: Blog / LinkedIn / X / Facebook / YouTube
Media Contact:
Bill Keeler
Semperis
Senior Director, PR & Comms
[email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/semperis-researcher-discovers-critical-active-directory-privilege-escalation-vulnerabilities-302860009.html
SOURCE Semperis
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- CANIDAE AND WALKER HAYES UNLEASH A HEARTFELT NEW ANTHEM FOR NATIONAL DOG DAY
- Chronograph and Perplexity Announce Integration of Private Capital Data into Perplexity Computer
- The D.H. Collective Awarded TX DIR Flood Early Warning System Contract, Bringing Together Texas Technology Leaders for More Resilient Communities
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share