Vulnerabilities & Exploits · Web App Attack

Shared MachineKey Turns One LMS Bug Into Fleet Risk

KnowledgeDeliver was not just exposed as a single bad server. A vendor-supplied ASP.NET machineKey was reused across deployments, so one leaked key let attackers forge trusted ViewState and compromise other internet-facing instances that copied the same secret.

Mandiant ties this to a zero-day in KnowledgeDeliver, tracked as CVE-2026-5426, affecting deployments before Feb. 24, 2026. The flaw allowed unauthenticated remote code execution through ViewState deserialization, and the same standardized web.config made the trust break cross-customer instead of local to one server.

The risk persists anywhere a vendor or operator reuses the same machineKey across ASP.NET instances. In that setup, patching one server does not fix the trust boundary if other deployments still accept forged signed requests.

4 sources · May 26

CVE-2026-5426

NVD KEV

CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 1% (59th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-27

Every edition of this story: Shared MachineKey Turns One LMS Bug Into Fleet Risk

More from today