CVE-2026-5426
CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 0.8% (55º percentile).
Vulnerabilità · 126 giorni fa
KnowledgeDeliver non è stato esposto solo come un singolo server difettoso. Una machineKey ASP.NET fornita dal vendor è stata riutilizzata tra i deployment, quindi una chiave trapelata ha permesso agli attacker di forgiare ViewState fidati e compromettere altre istanze esposte su Internet che avevano copiato lo stesso segreto.
CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 0.8% (55º percentile).
4 fonti che coprono questa storia
KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
CVE-2026-5426 enabled KnowledgeDeliver LMS attacks before February 24, 2026, leading to Cobalt Strike infections.
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability | Google Cloud Blog
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability Mandiant Google Threat Intelligence Group Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web…
Part of the PlainSec briefing for 2026-05-27