にゃん☆たく/takumi.a[verified]@taku888infinityActive Exploitation
The text reports real‑world exploitation of CVE‑2026‑5426, an RCE vulnerability in Knowledge Deliver, with attackers injecting malicious code during a late‑2025 incident.
Elusive[verified]@ElusivePrivacyActive Exploitation
Attackers exploited hardcoded ASP.NET machine keys in KnowledgeDeliver LMS (CVE‑2026‑5426) to gain unauthenticated RCE, deploying a Godzilla web shell and a Cobalt Strike beacon, demonstrating active exploitation of a zero‑day deserialization flaw.
White Rabbitx 🏴☠️[verified]@TheRabbitPyDisclosure
The post announces CVE‑2026‑5426, a critical ViewState RCE in KnowledgeDeliver caused by a hard‑coded machineKey, and notes vendor and third‑party advisories.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE‑2026‑5426 has been actively leveraged through ViewState deserialization to achieve unauthenticated RCE, deploy in‑memory web shells, and distribute Cobalt Strike, with detailed detection artifacts and IOC guidance provided.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE‑2026‑5426, a zero‑day ViewState deserialization vulnerability in KnowledgeDeliver LMS, is actively abused in the wild, with Mandiant reporting Godzilla web shell deployment and Cobalt Strike beacons.
PurpleOps[verified]@PurpleOps_ioPatch
The post highlights a class-level ASP.NET machineKey RCE vulnerability (CVE‑2026‑5426) and recommends per‑install key generation as the primary mitigation.
Cybersecurity News Everyday[verified]@TweetThreatNewsActive Exploitation
Mandiant reports CVE-2026-5426 is actively exploited in the wild, with attackers using BLUEBEAM and Cobalt Strike through a fake plugin to gain unauthenticated remote code execution via shared ASP.NET machine keys.
TechNadu[verified]@TechNaduActive Exploitation
The CVE has already been actively exploited, with attackers using it to deploy Cobalt Strike BEACON and Godzilla malware on the KnowledgeDeliver LMS platform.