CVE-2026-5426Active Exploitation

HIGHCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 16 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 30 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 46 mentions across 9 observed days

What's happening

  • Active exploitation reported across 30 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 29 signals
  • Disclosure: 8 classified signals
  • General: 5 classified signals
  • Peaked 5d ago at 16 mentions (2026-05-26); latest day: 1
  • 46 total mentions across 9 days

Deep dive

Activity timeline46 mentions / 9d
0481216Mentions · 2026-04-16: 1Mentions · 2026-04-17: 3Mentions · 2026-05-25: 8Mentions · 2026-05-26: 16Mentions · 2026-05-27: 10Mentions · 2026-05-28: 3Mentions · 2026-05-29: 2Mentions · 2026-06-01: 2Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-05-25: 4PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-27: 2Exploit Tool / Code · 2026-05-25: 2Exploit Tool / Code · 2026-05-26: 5Exploit Tool / Code · 2026-05-27: 2Exploit Tool / Code · 2026-05-28: 1Exploit Tool / Code · 2026-06-01: 1Active Exploitation · 2026-05-25: 5Active Exploitation · 2026-05-26: 10Active Exploitation · 2026-05-27: 8Active Exploitation · 2026-05-28: 3Active Exploitation · 2026-05-29: 2Active Exploitation · 2026-06-01: 2Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-05-26: 4Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 3Technical Details · 2026-05-25: 8Technical Details · 2026-05-26: 9Technical Details · 2026-05-27: 5Technical Details · 2026-05-28: 2Technical Details · 2026-06-01: 104-1604-1705-2505-2605-2705-2805-2906-0106-08
Signal classification6 categories
Active Exploitation
2860.9%
Disclosure
817.4%
General
510.9%
Patch
36.5%
Exploit
12.2%
PoC
12.2%
Referenced assets42 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-173
Disclosure3
2026-05-258
Active Exploitation4Disclosure1Exploit1General1PoC1
2026-05-2616
Active Exploitation11Disclosure2General2Patch1
2026-05-2710
Active Exploitation7Disclosure1General1Patch1
2026-05-283
Active Exploitation2Patch1
2026-05-292
Active Exploitation2
2026-06-012
Active Exploitation2
2026-06-081
General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 One shared key. Every deployment at risk. Attackers exploited CVE-2026-5426 in the KnowledgeDeliver LMS to gain unauthenticated RCE through hard-coded ASP-NET machineKeys, deploy the Godzilla (BLUEBEAM) web shell, and deliver Cobalt Strike Beacon on vulnerable internet-facing systems. Read 🠒 https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html

    Post summary

    The post reports real‑world exploitation of CVE‑2026‑5426, detailing the unauthenticated RCE vector and the deployment of web shells and Cobalt Strike on vulnerable systems.

    73821021016.9K
    1.9M followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Mandiant reported a CVE-2026-5426 ViewState deserialization exploiting shared KnowledgeDeliver machine keys, enabling unauthenticated RCE, BLUEBEAM web shell deployment, file tampering, and Cobalt Strike infection across targeted LMS deployments. https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/

    Post summary

    The text reports that CVE-2026-5426 is being actively exploited in the wild, enabling unauthenticated remote code execution on knowledge delivery systems via ViewState deserialization.

    0502125.8K
    22.5K followersView on X
  • Mathew@mittypk
    Disclosure

    Old technique, new zero-day CVE-2026-5426 in KnowledgeDeliver is related to hardcoded machine keys enabling ViewState deserialization attacks. If you're a defender in APJ, but especially Japan, this may be relevant to you: EN: https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability?e=48754805 JP: https://cloud.google.com/blog/ja/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability?e=48754805&hl=ja

    Post summary

    The post announces CVE-2026-5426, a new zero‑day involving hardcoded machine keys that allow ViewState deserialization attacks, and points to Google Cloud blog posts for detailed information, with no evidence of exploit code, active use, or available patch mentioned.

    0401551.5K
    1.3K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Learn how Mandiant uncovered the critical Knowledge Deliver RCE vulnerability (CVE-2026-5426) and how to protect your systems today. #Cybersecurity #RCE #Vulnerability #Mandiant #Infosec #CVE20265426 https://securityonline.info/knowledge-deliver-rce-vulnerability-cve-2026-5426/ https://t.co/bJhM8Gm5uX

    Post summary

    The tweet announces Mandiant’s discovery of the CVE‑2026‑5426 RCE vulnerability and urges readers to learn protection measures, but it contains no PoC, exploit, or patch details.

    02073671
    12.5K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Active Exploitation

    New Knowledge Deliver RCE Vulnerability Exploited in the Wild https://securityonline.info/knowledge-deliver-rce-vulnerability-cve-2026-5426/ 『(直訳)2025年後半、Mandiantは、侵害されたWebサーバーに関連する重大なセキュリティインシデントに対応しました。具体的には、影響を受けたサーバーは、日本で人気の高い学習管理システムであるKnowledge Deliverを稼働させていました。調査中に、研究者はCVE-2026-5426として追跡されているKnowledge Deliverの重大なリモートコード実行(RCE)脆弱性を発見しました。当初、正体不明の攻撃者はこの脆弱性をゼロデイ脆弱性として悪用しました。その結果、攻撃者は悪意のあるコードをプラットフォームに注入し、何も知らないユーザーを感染させました。』

    Post summary

    The text reports real‑world exploitation of CVE‑2026‑5426, an RCE vulnerability in Knowledge Deliver, with attackers injecting malicious code during a late‑2025 incident.

    100332.4K
    11.7K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    Ah 1/2 Hardcoded http://ASP.NET machine keys in KnowledgeDeliver LMS gave attackers unauthenticated RCE. CVE-2026-5426. Godzilla web shell deployed, followed by Cobalt Strike beacon. The deserialization flaw in the Japanese LMS was exploited as a zero-day no patch existed at time of attack. Source: BleepingComputer / SecurityWeek

    Post summary

    Attackers exploited hardcoded ASP.NET machine keys in KnowledgeDeliver LMS (CVE‑2026‑5426) to gain unauthenticated RCE, deploying a Godzilla web shell and a Cobalt Strike beacon, demonstrating active exploitation of a zero‑day deserialization flaw.

    31020122
    181 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Mandiant warns of CVE-2026-5426: a critical KnowledgeDeliver patch fixing hardcoded http://ASP.NET machine keys exploited to deploy BLUEBEAM web shells. #KnowledgeDeliver #CVE20265426 #LMS #CyberSecurity #ThreatIntel #Mandiant #RCE #WebShell https://meterpreter.org/knowledgedeliver-cve-2026-5426-patch-aspnet-rce/ https://t.co/985CvEVuqb

    Post summary

    Mandiant highlights that CVE‑2026‑5426, which allows exploitation of hardcoded ASP.NET machine keys in KnowledgeDeliver, is being actively used to deploy web shells and that a patch is available to mitigate the issue.

    01021338
    12.5K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🧩 CVE‑2026‑5426 – Digital Knowledge KnowledgeDeliver ViewState RCE (Critical): A hard-coded http://ASP.NET/IIS machineKey in KnowledgeDeliver deployments before February 24, 2026 lets attackers bypass ViewState validation and send malicious ViewState payloads that can execute arbitrary code remotely. CVSS 9.8, published today, with vendor and third-party advisories tracking the issue as critical. https://www.tenable.com/cve/CVE-2026-5426 #CVE20265426 #ASPNet #IIS #RCE #WebAppSec #ThreatIntel

    Post summary

    The post announces CVE‑2026‑5426, a critical ViewState RCE in KnowledgeDeliver caused by a hard‑coded machineKey, and notes vendor and third‑party advisories.

    10030105
    1.7K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Active Exploitation

    🚨 #Alerta de #Ciberseguridad: Explotación Zero-Day CVE-2026-5426 en LMS "#KnowledgeDeliver" https://www.newstecnicas.com/2026/05/alerta-de-ciberseguridad-explotacion.html

    Post summary

    The message reports that CVE-2026-5426 is currently being exploited against the LMS KnowledgeDeliver, but it lacks specific technical or patch details.

    0102067
    1.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Critical KnowledgeDeliver LMS zero-day (CVE-2026-5426) exploited via hardcoded http://ASP.NET machine keys. Threat actors achieved unauthenticated RCE, deployed in-memory web shells, and infected visitors with Cobalt Strike through fake security prompts. Technical breakdown: • Vulnerability: Identical machineKey values across deployments enabled ViewState deserialization attacks (pre-Feb 24, 2026 installs) • Post-exploitation: BLUEBEAM web shell in w3wp.exe memory, icacls privilege escalation, JavaScript injection for fake security alerts • Attack chain: ViewState RCE → BLUEBEAM deployment → file tampering → Cobalt Strike distribution via social engineering • Detection artifacts: Event ID 1316 with "Event code: 4009" indicating ViewState failures, suspicious w3wp.exe child processes (cmd.exe, whoami, powershell) • IOCs: Anomalous concatenated User-Agent strings, unauthorized .js/.aspx modifications in web root Hunt for Event ID 1316 from http://ASP.NET sources and w3wp.exe spawning system commands. Full detection rules available in Mandiant SecOps rule packs. #DFIR_Radar

    Post summary

    CVE‑2026‑5426 has been actively leveraged through ViewState deserialization to achieve unauthenticated RCE, deploy in‑memory web shells, and distribute Cobalt Strike, with detailed detection artifacts and IOC guidance provided.

    11010314
    1.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-5426 zero-day in KnowledgeDeliver LMS exploited via hardcoded http://ASP.NET machine keys for ViewState deserialization attacks. Mandiant confirms Godzilla web shell deployment and Cobalt Strike beacons. #DFIR_Radar https://t.co/Cmy6PCIkKa

    Post summary

    CVE‑2026‑5426, a zero‑day ViewState deserialization vulnerability in KnowledgeDeliver LMS, is actively abused in the wild, with Mandiant reporting Godzilla web shell deployment and Cobalt Strike beacons.

    10010300
    1.8K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A brief list of trending CVEs is presented with no additional context or technical detail.

    00020150
    1.7K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    CVE-2026-5426 is a class of bug, not a vendor slip. Ship a static http://ASP.NET machineKey and every customer shares the same RCE key. Microsoft flagged public-machineKey abuse in Feb 2025; ViewState deserialization keeps collecting. Fix: per-install key generation, never a baked-in default.

    Post summary

    The post highlights a class-level ASP.NET machineKey RCE vulnerability (CVE‑2026‑5426) and recommends per‑install key generation as the primary mitigation.

    01010326
    575 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Mandiant linked a KnowledgeDeliver breach to shared http://ASP.NET machine keys, enabling unauthenticated RCE (CVE-2026-5426). Attackers deployed BLUEBEAM and later Cobalt Strike via a fake plugin. #Japan #KnowledgeDeliver #CVE20265426 https://ift.tt/FZqOwnt

    Post summary

    Mandiant reports CVE-2026-5426 is actively exploited in the wild, with attackers using BLUEBEAM and Cobalt Strike through a fake plugin to gain unauthenticated remote code execution via shared ASP.NET machine keys.

    00011243
    4.3K followersView on X
  • TechNadu@TechNadu
    Active Exploitation

    Attackers exploited CVE-2026-5426 in the KnowledgeDeliver LMS platform to deploy Cobalt Strike BEACON and Godzilla malware. GTIG says the flaw abused hardcoded ASP. NET machine keys for unauthenticated RCE via malicious ViewState payloads. #CyberSecurity #CVE20265426 #CobaltStrike #Malware

    Post summary

    The CVE has already been actively exploited, with attackers using it to deploy Cobalt Strike BEACON and Godzilla malware on the KnowledgeDeliver LMS platform.

    10000146
    10.1K followersView on X
  • Machina Record@MachinaRecord
    Patch

    🩹マイクロソフト、SharePointの深刻なRCE脆弱性にパッチ(CVE-2026-45659) ⚠️ハッカーがKnowledgeDeliverのゼロデイを悪用し、Webシェルとバックドアを展開(CVE-2026-5426) 〜サイバーアラート5月27日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45807/

    Post summary

    Microsoft has issued a patch for a critical SharePoint RCE (CVE‑2026‑45659), while hackers are actively exploiting a KnowledgeDeliver zero‑day (CVE‑2026‑5426) to deploy web shells and backdoors.

    00010221
    1.3K followersView on X
  • Threat ResQ™@ThreatResq
    Active Exploitation

    Hackers exploited a critical zero-day in KnowledgeDeliver to deploy the Godzilla web shell. The unauthenticated flaw (CVE-2026-5426) stems from a shared hardcoded machine key. https://www.bleepingcomputer.com/news/security/knowledgedeliver-flaw-exploited-as-a-zero-day-to-install-web-shells/ #0day #KnowledgeDeliver #Godzilla #CVE #CybersecurityNews #ThreatResQ

    Post summary

    Hackers exploited the unauthenticated CVE-2026-5426 in KnowledgeDeliver, deploying the Godzilla web shell because of a shared hardcoded machine key, with no patch or workaround mentioned.

    00010132
    47 followersView on X
  • AI Security Gateway@AISGateway
    General

    Hard-coded credentials in enterprise software aren't just a legacy problem. CVE-2026-5426 in KnowledgeDeliver LMS shows they're still enabling zero-day exploitation in 2026. Web shells + Cobalt Strike via a static http://ASP.NET machine key. Unglamorous. Devastating.

    Post summary

    The post warns that CVE‑2026‑5426 involves hard‑coded credentials that could be exploited via web shells and Cobalt Strike, but it does not provide a PoC, patch, or evidence of active exploitation.

    1000076
    40 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-5426 2 - CVE-2023-29218 3 - CVE-2026-2031 4 - CVE-2026-41096 5 - CVE-2024-53141 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The content lists the top five trending CVEs with no supporting details, proofs of concept, or actionable information.

    00010199
    1.7K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-5426: KnowledgeDeliver Hard-Coded Machine Key Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04kvXD90

    Post summary

    The link references a CVE title but provides no substantive details about exploitation, mitigation, or technical specifics.

    0000037
    31 followersView on X

Explore more