Start with Identity

CVE-2026-25177KerberLoss, invisible-Unicode SPN uniqueness bypass

high · CVSS 8.8
Product: Active Directory (Kerberos SPNs)Vendor: MicrosoftDisclosed: 2026-03-10Status: PatchedNVD ↗

What broke

Active Directory's SPN uniqueness check did not treat invisible-Unicode look-alikes as collisions. An attacker who can write an SPN registers a twin of HTTP/app.contoso.com, intercepts Kerberos traffic, and can downgrade the client to NTLM. Semperis and Shai Laron named it KerberLoss. CVSS 8.8. Microsoft patched in March 2026.

Why it matters

SPN uniqueness is the only thing standing between "I can write a servicePrincipalName" and "I am the app." Combined with Ghost SPNs and ResetNightmare, 2026 made AD's name-uniqueness story look as fragile as SAML's signature-binding story.

What to do

  • Deploy the March 2026 AD / Kerberos updates on every DC.
  • Alert on new SPNs that contain non-ASCII characters. There is almost never a business reason.
  • Restrict Validated write to service principal name to the smallest set of computer accounts that need it.
  • Semperis published detection guidance. Use it even after you patch.

After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

  • Rotate the krbtgt account twice, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
  • Audit AD CS certificate templates for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See certificate lifecycle.
  • Review privileged group membership and delegation rights (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
  • Hunt for tickets with anomalous lifetimes or encryption types, and for authentications to services that identity never touches.
  • Treat any issued certificate as a durable credential: revoking a user's password does not revoke a certificate that authenticates as them. See privilege escalation and lateral movement.

Sources

Last reviewed By SWI Community TeamSuggest a correctionHow we research

Technique

This CVE is an instance of Kerberoasting. Any authenticated domain user can request a Kerberos service ticket for any service principal, and that ticket is encrypted with the service account's own password hash, offline and unrateable to test.

Know a primary source we should add, or a patch status that has changed? Email community@startwithidentity.com. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.