CVE-2026-5426
KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 02, 2026
- Published Date
- April 16, 2026
- Last Updated
- May 27, 2026
- Vendor
- Digital Knowledge
- Product
- KnowledgeDeliver
- Description
- Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
CVSS Scores
CVSS v3.1
9.1 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SSVC Information
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (2026-05-25 07:00:00 UTC) Source
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| The Shadowserver (via CIRCL) | 2026-05-25 07:00:00 UTC |
Recent Mentions
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
Source: TheHackerNews • Published: 2026-05-26 05:19:38 UTC
A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon.
The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel