PULSE NAME
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
WHITE AlienVault 2026-05-25 Modified: 2026-05-25
2
IOCs
LOW VOLUME
In late 2025, an unknown threat actor exploited a critical zero-day vulnerability in KnowledgeDeliver, a Learning Management System widely used in Japan. The vulnerability, tracked as CVE-2026-5426, allowed unauthenticated remote code execution through ViewState deserialization attacks. The issue stemmed from identical hardcoded ASP.NET machine keys distributed across multiple customer deployments in the vendor's configuration files. Attackers obtained these keys from one deployment and used them to compromise other internet-facing instances. Following initial access, threat actors deployed the BLUEBEAM in-memory web shell, modified JavaScript files to display fake security alerts, and tricked users into installing malicious software that delivered Cobalt Strike BEACON backdoors. The attack demonstrates the severe risks of shared secrets in deployment templates and highlights the importance of unique cryptographic keys per installation.
Indicators of Compromise (2)
All CVE FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2026-5426 2026-05-25
FileHash-SHA256 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2 2026-05-25