New Knowledge Deliver RCE Vulnerability Exploited in the Wild
ID: 7a5c6e14-dea9-5ec2-abd2-429d96a5fe2c
STIX ID: report--7a5c6e14-dea9-5ec2-abd2-429d96a5fe2c
Feed Name: securityonline.info
Mandiant investigated active exploitation of a critical Knowledge Deliver RCE (CVE-2026-5426) caused by vendor-shared machineKey values; attackers used malicious ViewState payloads to achieve deserialization-based RCE, deployed an in-memory BLUEBEAM web shell in the IIS process, altered file-system permissions, and delivered a Cobalt Strike BEACON backdoor. Defenders are advised to rotate machine keys per instance, monitor Windows Application logs (Event ID 1316) and unusual child processes of w3wp.exe, implement file integrity monitoring, and restrict system access to known corporate IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
