Summary
Canonical patched a critical vulnerability (CVE-2026-12249) in ADSys that allows attackers to poison the Ubuntu system trust store by intercepting unencrypted certificate enrollment requests. This flaw enables persistent decryption of TLS traffic and full compromise of encrypted communications on affected hosts.
Take Action:
If you manage Ubuntu machines connected to Active Directory through ADSys, update ADSys to version 0.16.3 or later on all of them. Oder versions fetch certificates over unencrypted HTTP and let an attacker plant a fake root certificate that exposes all encrypted traffic on the machine. After updating, check each machine's trusted certificates for any unfamiliar root certificates and remove them, since a machine that was already compromised stays exposed even after the patch.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)