DEV Community

Cover image for Canonical Patches Critical Trust Store Poisoning Flaw in ADSys
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Canonical Patches Critical Trust Store Poisoning Flaw in ADSys

Summary

Canonical patched a critical vulnerability (CVE-2026-12249) in ADSys that allows attackers to poison the Ubuntu system trust store by intercepting unencrypted certificate enrollment requests. This flaw enables persistent decryption of TLS traffic and full compromise of encrypted communications on affected hosts.

Take Action:

If you manage Ubuntu machines connected to Active Directory through ADSys, update ADSys to version 0.16.3 or later on all of them. Oder versions fetch certificates over unencrypted HTTP and let an attacker plant a fake root certificate that exposes all encrypted traffic on the machine. After updating, check each machine's trusted certificates for any unfamiliar root certificates and remove them, since a machine that was already compromised stays exposed even after the patch.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)