← Back to Feed
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
CVE-2026-5426
May 25, 2026 · Google Cloud Security · Severity: CRITICAL
Mandiant responded to a breach of a KnowledgeDeliver Learning Management System, identifying a critical unauthenticated remote code execution vulnerability. The issue stems from identical hardcoded ASP.NET machine keys shared across customer deployments, allowing attackers to craft malicious ViewState payloads. The attackers injected code to infect visitors of the compromised platform, tracked now as CVE-2026-5426.
Key Takeaways
- Hardcoded ASP.NET machine keys across deployments enable unauthenticated remote code execution.
- Attackers exploit ViewState deserialization to inject malicious code into KnowledgeDeliver.
- CVE-2026-5426 is a zero-day abusing identical keys in multiple customer environments.