As cited
Copy frozen at (site build).
vulnerabilities
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
Mandiant identified a critical remote code execution vulnerability in KnowledgeDeliver, a Learning Management System, stemming from hardcoded and identical ASP.NET machine keys across customer deployments that allowed unauthenticated attackers to craft malicious ViewState payloads. An unknown threat actor exploited this as a zero-day (now tracked as CVE-2026-5426) to deploy the BLUEBEAM web shell, tamper with JavaScript files to distribute Cobalt Strike BEACON backdoors, and compromise user workstations. Organizations running vulnerable KnowledgeDeliver instances deployed before February 24, 2026 are affected and should implement patches and monitor for ViewState deserialization attacks.
Why it matters: This is an unauthenticated RCE affecting internet-facing Learning Management Systems with known exploitation in the wild; patching or isolating affected KnowledgeDeliver instances should be prioritized.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
Mandiant identified a critical remote code execution vulnerability in KnowledgeDeliver, a Learning Management System, stemming from hardcoded and identical ASP.NET machine keys across customer deployments that allowed unauthenticated attackers to craft malicious ViewState payloads. An unknown threat actor exploited this as a zero-day (now tracked as CVE-2026-5426) to deploy the BLUEBEAM web shell, tamper with JavaScript files to distribute Cobalt Strike BEACON backdoors, and compromise user workstations. Organizations running vulnerable KnowledgeDeliver instances deployed before February 24, 2026 are affected and should implement patches and monitor for ViewState deserialization attacks.
Why it matters: This is an unauthenticated RCE affecting internet-facing Learning Management Systems with known exploitation in the wild; patching or isolating affected KnowledgeDeliver instances should be prioritized.
- Source published
- First seen by Cybersecurity Tracker