KnowledgeDeliver Exploitation via ViewState Deserialization
Score: 9/10

KnowledgeDeliver Exploitation via ViewState Deserialization

Unknown threat actors are exploiting CVE-2026-5426 in KnowledgeDeliver LMS using hardcoded machine keys to achieve RCE and deploy BLUEBEAM web shells and Cobalt Strike.

Executive Summary

In late 2025 and early 2026, threat actors targeted KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, by exploiting a critical vulnerability (CVE-2026-5426) caused by identical pre-shared ASP.NET machine keys across deployments. This zero-day allows unauthenticated Remote Code Execution (RCE) via malicious ViewState payloads, enabling attackers to gain control over web servers without valid credentials.

Following initial exploitation, attackers deployed the BLUEBEAM (Godzilla) in-memory web shell within the IIS worker process and modified application JavaScript files to prompt users to download fake security updates. This social engineering tactic led to Cobalt Strike BEACON infections on user workstations. The use of target-specific encryption keys for the Cobalt Strike payloads suggests a deliberate and tailored approach to the targeted organizations.

This campaign underscores the high risk of standardized deployment templates using hardcoded secrets. Organizations using KnowledgeDeliver versions deployed before February 24, 2026, are at significant risk and must immediately rotate their ASP.NET machine keys to prevent further exploitation.

Key Details

Threat Name

CVE-2026-5426

Affects

KnowledgeDeliver, KnowledgeDeliver installations deployed before Feb. 24, 2026

Adversary

—

Malware/Tools

BLUEBEAM, Cobalt Strike

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details9
Detection Guidance9
Enterprise Relevance9
Clarity & Structure10
Technical Depth8

Sources