Vulnerabilities · 111 days ago

Shared MachineKey Turns One LMS Bug Into Fleet Risk

KnowledgeDeliver was not just exposed as a single bad server. A vendor-supplied ASP.NET machineKey was reused across deployments, so one leaked key let attackers forge trusted ViewState and compromise other internet-facing instances that copied the same secret.

Mandiant ties this to a zero-day in KnowledgeDeliver, tracked as CVE-2026-5426, affecting deployments before Feb. 24, 2026. The flaw allowed unauthenticated remote code execution through ViewState deserialization, and the same standardized web.config made the trust break cross-customer instead of local to one server.

The risk persists anywhere a vendor or operator reuses the same machineKey across ASP.NET instances. In that setup, patching one server does not fix the trust boundary if other deployments still accept forged signed requests.

CVE-2026-5426

NVD KEV

CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 1% (59th percentile).

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories