Mandiant
Critical RCE Vulnerability in KnowledgeDeliver LMS Exploited by Hackers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In late 2025, a critical vulnerability (CVE-2026-5426) was discovered in the KnowledgeDeliver Learning Management System, allowing unauthenticated remote code execution via ViewState deserialization. This flaw, stemming from identical ASP.NET machine keys across deployments, enabled threat actors to inject malicious code and deploy the BLUEBEAM web shell. The vulnerability has been actively exploited, impacting numerous organizations using KnowledgeDeliver, particularly in Japan. Mandiant's investigation revealed that the attackers modified JavaScript files to deceive users into downloading malicious software. The exploitation of this zero-day vulnerability poses a significant risk to users and organizations relying on this LMS. As of May 2026, the threat remains active, with ongoing attacks reported.
Key Points: • CVE-2026-5426 allows unauthenticated remote code execution in KnowledgeDeliver LMS. • Attackers exploit identical ASP.NET machine keys to deploy the BLUEBEAM web shell. • Organizations using KnowledgeDeliver, especially in Japan, are at high risk of compromise.