CVE-2026-12249Active Exploitation

MEDIUMCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA certificate from the Active Directory Certificate Services server (GetCACert). An unauthenticated network attacker positioned between the managed Ubuntu host and the configured AD CS CA hostname can conduct a Man-in-the-Middle (MITM) attack. By intercepting the plaintext HTTP request, the attacker can supply an arbitrary, attacker-controlled Root CA certificate. Because the system automatically accepts this certificate and registers it into the local system trust store via update-ca-certificates, this results in system-wide trust store poisoning. Consequently, TLS clients utilizing the operating system trust store on the affected machine will accept rogue certificates for arbitrary domains, enabling persistent decryption and interception of subsequent TLS connections. This issue is resolved in version v0.16.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-23: 2Active Exploitation · 2026-06-23: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-23: 106-23
Signal classification2 categories
Active Exploitation
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Canonical Ubuntu (CVE-2026-12249) https://vuldb.com/vuln/372740/cti

    Post summary

    CTI team reports many attacks targeting Ubuntu CVE-2026-12249, indicating that the vulnerability is being actively exploited.

    00000100
    2.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Canonical ADSys AD CS Auto-Enrollment Trust Store Poisoning via Plaintext HTTP (CVE-2026-12249) During AD CS certificate auto-enrollment, Canonical ADSys (the Active Directory Group Policy client for Ubuntu) requests the CA certificate over plaintext HTTP instead of HTTPS in its vendored Samba script. An unauthenticated attacker with a man-in-the-middle position between the Ubuntu host and the AD CS CA can intercept the GetCACert request and return an arbitrary attacker-controlled Root CA. The system automatically registers that certificate into the local trust store via update-ca-certificates, poisoning the system-wide trust store. TLS clients using the OS trust store will then accept rogue certificates for any domain, enabling persistent decryption and interception of the host's subsequent TLS traffic. 👉Upgrade to Canonical ADSys v0.16.3.

    Post summary

    A critical CA certificate poisoning flaw in Canonical ADSys enables an attacker to inject a rogue root CA; upgrading to v0.16.3 addresses the vulnerability.

    00000101
    226 followersView on X

Explore more