logo

KnowledgeDeliver flaw exploited as a zero-day to install web shells

ID: 3208f243-3bb6-5f6c-a44e-67ee31be47c3

STIX ID: report--3208f243-3bb6-5f6c-a44e-67ee31be47c3

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Ionut Ilascu

...
...

Mandiant reported that KnowledgeDeliver LMS instances used a standardized web.config with a hardcoded ASP.NET machineKey (CVE-2026-5426), enabling ViewState deserialization attacks that were exploited as a zero-day to gain RCE; threat actors used the flaw to install a Cobalt Strike beacon and deploy the Godzilla (BlueBeam) .NET web shell, modifying web content to trick users into a malicious installer and indicating multi-customer exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.