Mandiant Critical RCE Vulnerability in KnowledgeDeliver LMS Exploited by Hackers
Article Content
- •CVE-2026-5426 allows unauthenticated remote code execution in KnowledgeDeliver LMS.
- •Attackers exploit identical ASP.NET machine keys to deploy the BLUEBEAM web shell.
- •Organizations using KnowledgeDeliver, especially in Japan, are at high risk of compromise.
In late 2025, a critical vulnerability (CVE-2026-5426) was discovered in the KnowledgeDeliver Learning Management System, allowing unauthenticated remote code execution via ViewState deserialization. This flaw, stemming from identical ASP.NET machine keys across deployments, enabled threat actors to inject malicious code and deploy the BLUEBEAM web shell. The vulnerability has been actively exploited, impacting numerous organizations using KnowledgeDeliver, particularly in Japan. Mandiant's investigation revealed that the attackers modified JavaScript files to deceive users into downloading malicious software. The exploitation of this zero-day vulnerability poses a significant risk to users and organizations relying on this LMS. As of May 2026, the threat remains active, with ongoing attacks reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track APT41, Bluebeam and Digital Knowledge in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE, and EPA…