CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 310

As cited

Copy frozen at (site build).

vulnerabilities

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Mandiant identified a critical remote code execution vulnerability in KnowledgeDeliver, a Learning Management System, stemming from hardcoded and identical ASP.NET machine keys across customer deployments that allowed unauthenticated attackers to craft malicious ViewState payloads. An unknown threat actor exploited this as a zero-day (now tracked as CVE-2026-5426) to deploy the BLUEBEAM web shell, tamper with JavaScript files to distribute Cobalt Strike BEACON backdoors, and compromise user workstations. Organizations running vulnerable KnowledgeDeliver instances deployed before February 24, 2026 are affected and should implement patches and monitor for ViewState deserialization attacks.

Why it matters: This is an unauthenticated RCE affecting internet-facing Learning Management Systems with known exploitation in the wild; patching or isolating affected KnowledgeDeliver instances should be prioritized.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Mandiant identified a critical remote code execution vulnerability in KnowledgeDeliver, a Learning Management System, stemming from hardcoded and identical ASP.NET machine keys across customer deployments that allowed unauthenticated attackers to craft malicious ViewState payloads. An unknown threat actor exploited this as a zero-day (now tracked as CVE-2026-5426) to deploy the BLUEBEAM web shell, tamper with JavaScript files to distribute Cobalt Strike BEACON backdoors, and compromise user workstations. Organizations running vulnerable KnowledgeDeliver instances deployed before February 24, 2026 are affected and should implement patches and monitor for ViewState deserialization attacks.

Why it matters: This is an unauthenticated RCE affecting internet-facing Learning Management Systems with known exploitation in the wild; patching or isolating affected KnowledgeDeliver instances should be prioritized.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary