Skip to content
Critical RCE Vulnerability in KnowledgeDeliver LMS Exploited by Hackers

Critical RCE Vulnerability in KnowledgeDeliver LMS Exploited by Hackers

First seen 25 May 2026, 16:05 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 26, 2026 at 15:31 UTC

In late 2025, a critical vulnerability (CVE-2026-5426) was discovered in the KnowledgeDeliver Learning Management System, allowing unauthenticated remote code execution via ViewState deserialization. This flaw, stemming from identical ASP.NET machine keys across deployments, enabled threat actors to inject malicious code and deploy the BLUEBEAM web shell. The vulnerability has been actively exploited, impacting numerous organizations using KnowledgeDeliver, particularly in Japan. Mandiant's investigation revealed that the attackers modified JavaScript files to deceive users into downloading malicious software. The exploitation of this zero-day vulnerability poses a significant risk to users and organizations relying on this LMS. As of May 2026, the threat remains active, with ongoing attacks reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 107d ago How this analysis works

Timeline

2025-12-01
Initial exploitation observed
Threat actors began exploiting the CVE-2026-5426 vulnerability in real-world attacks, deploying BLUEBEAM web shells.
Gbhackers
2026-04-16
CVE-2026-5426 published
A critical vulnerability in KnowledgeDeliver LMS was officially published, enabling RCE through ViewState deserialization.
Mandiant
Recent
Ongoing attacks reported
Mandiant continues to monitor active exploitation of the vulnerability, with multiple organizations affected.
Cybersecuritynews

More articles in this cluster (17)

Following this threat?

Track APT41, Bluebeam and Digital Knowledge in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed