---
schema: 1
kind: vulnerability
title: "CVE-2026-5426 — Digital Knowledge KnowledgeDeliver LMS: pre-shared ASP.NET machineKey enables ViewState deserialization RCE, exploited as a zero-day"
headline: "CVE-2026-5426 — Digital Knowledge KnowledgeDeliver LMS: pre-shared ASP.NET machineKey enables ViewState deserialization RCE, exploited as a zero-day"
summary: "Mandiant / Google Threat Intelligence Group published an incident-response investigation into a late-2025 compromise of a web server running KnowledgeDeliver, an ASP.NET learning-management system from Japan-based Digital Knowledge that is widely deployed in Japanese enterprise and education environments (Google …"
discovered_at: "2026-05-26T05:00:03Z"
event_date: 2026-05-25
run_id: 2026-05-26-ae9d0d4b
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - pre-auth
  - zero-day
regions:
  - apac
  - global
sectors:
  - education
  - technology
entities: []
cves:
  - id: CVE-2026-5426
    cvss: n/a
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/"
    publisher: "Google Threat Intelligence Group, 2026-05-25"
    role: primary
  - url: "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0009.md"
    publisher: Mandiant Vulnerability Disclosures MNDT-2026-0009
    role: corroborating
closed_sources: []
evidence:
  - quote: "Mandiant / Google Threat Intelligence Group published an incident-response investigation into a late-2025 compromise of a web server running KnowledgeDeliver, an ASP.NET learning-management system from Japan-based Digital Knowledge that is widely deployed in Japanese enterprise and education …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Audit ASP.NET estates for shared / default `machineKey` values and rotate to unique per-deployment keys** — the KnowledgeDeliver compromise (§ 2, CVE-2026-5426) is a pre-shared-key ViewState deserialization RCE; the exposure exists in any .NET app that ships or reuses a default key. Hunt Windows Application-log EID `1316` and `w3wp.exe` spawning shells on web servers ([Google Threat Intelligence Group, 2026-05-25](https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/))."
migrated_from: briefs/2026-05-26.md
---

Mandiant / Google Threat Intelligence Group published an incident-response investigation into a late-2025 compromise of a web server running **KnowledgeDeliver**, an ASP.NET learning-management system from Japan-based Digital Knowledge that is widely deployed in Japanese enterprise and education environments ([Google Threat Intelligence Group, 2026-05-25](https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/); [Mandiant Vulnerability Disclosures MNDT-2026-0009](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0009.md)). The root cause (CVE-2026-5426) is **identical pre-shared ASP.NET `machineKey` values shipped across all customer installations by default**: any party who recovers the hardcoded key from one instance can forge a valid signed/encrypted `ViewState` payload and replay it against any other deployment. Because ASP.NET `ViewState` is deserialized through `ObjectStateFormatter` → `BinaryFormatter`, a forged payload yields arbitrary .NET object-graph deserialization and remote code execution ([`T1190`](https://attack.mitre.org/techniques/T1190/)). Mandiant states the flaw was exploited as a zero-day prior to the 2026-02-24 patch.

Post-exploitation, the actor deployed **BLUEBEAM** (a variant of the Godzilla web shell) that runs entirely inside the IIS worker process `w3wp.exe` — no shell file on disk — receiving commands over encrypted HTTP POST ([`T1505.003`](https://attack.mitre.org/techniques/T1505/003/), [`T1071.001`](https://attack.mitre.org/techniques/T1071/001/)), then injected content into the LMS to mount a watering-hole attack against its users ([`T1189`](https://attack.mitre.org/techniques/T1189/)). Targeting is Japan-primary, but the transferable lesson is broad and urgent for CH/EU public-sector .NET estates: **audit every ASP.NET application for shared or default `machineKey` values and rotate to unique, cryptographically strong per-deployment keys** — there is no default-config toggle that removes the shared-key risk. Hunt for Windows Application-log Event ID `1316` (ViewState validation failure — Mandiant notes even successful exploitation generated these) on LMS-adjacent web servers, and for `w3wp.exe` spawning `cmd.exe`/`powershell.exe`/`cscript.exe` or making unexpected outbound connections (Sysmon EID 1 with a parent-image filter on `w3wp.exe`). Because BLUEBEAM is memory-resident with no on-disk shell file, live-memory collection on the IIS worker is the primary post-exploitation detection path.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-9058 | Szafir SDK (KIR) qualified e-signature library | 9.3 (CVSS 4.0) | n/a | No | Not reported | v463 | [CERT Polska](https://cert.pl/en/posts/2026/05/CVE-2026-9058/) |
| CVE-2026-5426 | Digital Knowledge KnowledgeDeliver LMS (ASP.NET) | n/a | n/a | No | Yes (zero-day, pre-2026-02-24) | 2026-02-24 release | [Mandiant GTIG](https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/) |
