← Back to Feed

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

CVE-2026-5426

May 25, 2026 · Google Cloud Security · Severity: CRITICAL

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver.

Key Takeaways

  • Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE).
  • 24, 2026 relied on a standardized web.config file provided by the vendor.
☕ Buy a Coffee