Skip to content

CVE-2026-5426

CVE

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
May 25, 2026
Last Seen
May 27, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A severe vulnerability known as BadHost (CVE-2026-48710) has been identified in the Starlette framework, affecting millions of AI applications, including those built on FastAPI. This flaw allows unauthenticated attackers to bypass authentication controls by manipulating HTTP Host headers, potentiall...

In late 2025, a critical vulnerability (CVE-2026-5426) was discovered in the KnowledgeDeliver Learning Management System, allowing unauthenticated remote code execution via ViewState deserialization. This flaw, stemming from identical ASP.NET machine keys across deployments, enabled threat actors to...

Public Exploits

Checking GitHub for proof-of-concept code…