← Back to Feed
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
CVE-2026-5426
May 25, 2026 · Google Cloud Security · Severity: CRITICAL
Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver.
Key Takeaways
- Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE).
- 24, 2026 relied on a standardized web.config file provided by the vendor.