CVE-2026-5426
CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 0.8% (55º percentile).
Vulnerabilità ed exploit · Attacco ad app web
KnowledgeDeliver non è stato esposto solo come un singolo server difettoso. Una machineKey ASP.NET fornita dal vendor è stata riutilizzata tra i deployment, quindi una chiave trapelata ha permesso agli attacker di forgiare ViewState fidati e compromettere altre istanze esposte su Internet che avevano copiato lo stesso segreto.
4 fonti · 27 mag
CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 0.8% (55º percentile).
BleepingComputer
KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
originaleSecurityWeek
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.
originaleThe Hacker News
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
CVE-2026-5426 enabled KnowledgeDeliver LMS attacks before February 24, 2026, leading to Cobalt Strike infections.
originalePart of the PlainSec briefing for 2026-05-25
Every edition of this story: Shared MachineKey Trasforma un Bug di LMS in un Rischio per l'Intera Flotta