CVE-2026-5426
CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 1% (59th percentile).
Vulnerabilities · 111 days ago
KnowledgeDeliver was not just exposed as a single bad server. A vendor-supplied ASP.NET machineKey was reused across deployments, so one leaked key let attackers forge trusted ViewState and compromise other internet-facing instances that copied the same secret.
Mandiant ties this to a zero-day in KnowledgeDeliver, tracked as CVE-2026-5426, affecting deployments before Feb. 24, 2026. The flaw allowed unauthenticated remote code execution through ViewState deserialization, and the same standardized web.config made the trust break cross-customer instead of local to one server.
The risk persists anywhere a vendor or operator reuses the same machineKey across ASP.NET instances. In that setup, patching one server does not fix the trust boundary if other deployments still accept forged signed requests.
CVSS 7.5 HIGH: hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026… EPSS 1% (59th percentile).
4 sources covering this story
KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
CVE-2026-5426 enabled KnowledgeDeliver LMS attacks before February 24, 2026, leading to Cobalt Strike infections.
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability | Google Cloud Blog
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability Mandiant Google Threat Intelligence Group Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web…
Part of the PlainSec briefing for 2026-05-27