Biggest? How about serving TLS certs when doing direct IP access? Or how about leaking sub domains in TLS certs?
I, as a mediocre hacker, cough, security advisor, cough, use certs to find vulnerable subdomains all the time. Or at least. I get to play around in your test envs.
Edit: Ok, the problem in the topic is also not good.