← Back to Feed

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

CVE-2026-5426

May 25, 2026 · Google Cloud Security · Severity: CRITICAL

Mandiant investigated a compromised KnowledgeDeliver server, finding a vulnerability caused by identical hardcoded ASP.NET machine keys across deployments. This allowed an unknown threat actor to perform ViewState deserialization and achieve unauthenticated remote code execution. The report notes similarities to prior ViewState deserialization attacks, and the issue is tracked as CVE-2026-5426.

Key Takeaways

  • Shared ASP.NET machine keys in web.config expose KnowledgeDeliver to deserialization attacks.
  • ViewState payloads crafted with known keys let attackers execute code remotely.
  • CVE-2026-5426 reflects a pattern seen in Sitecore and Microsoft-related incidents.
☕ Buy a Coffee