KnowledgeDeliver flaw exploited as a zero-day to install web shells
ID: 3208f243-3bb6-5f6c-a44e-67ee31be47c3
STIX ID: report--3208f243-3bb6-5f6c-a44e-67ee31be47c3
Feed Name: Bleeping Computer
Threat Score
Mandiant reported that KnowledgeDeliver LMS instances used a standardized web.config with a hardcoded ASP.NET machineKey (CVE-2026-5426), enabling ViewState deserialization attacks that were exploited as a zero-day to gain RCE; threat actors used the flaw to install a Cobalt Strike beacon and deploy the Godzilla (BlueBeam) .NET web shell, modifying web content to trick users into a malicious installer and indicating multi-customer exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
