Threat reportZero-DayTL-2026-0577

KnowledgeDeliver LMS ViewState Deserialization Zero-Day CVE-2026-5426 — Unauthenticated RCE via Shared ASP.NET machineKey + BLUEBEAM (Godzilla) Web Shell and Cobalt Strike BEACON Watering Hole

criticalMONITORING

KnowledgeDeliver LMS ViewState Deserialization Zero-Day (TL-2026-0577), also tracked as KnowledgeDeliver ViewState Zero-Day, is a critical-severity zero-day vulnerability scored CVSS 9.8, first published 2026-05-25. It has no confirmed attribution, affects Digital Knowledge Corporation KnowledgeDeliver (LMS), references 1 CVE (CVE-2026-5426), maps to 23 MITRE ATT&CK techniques (T1005, T1033, T1036), and is covered by 9 detection rules and 25 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0577

Threat ID
TL-2026-0577
Also known as
KnowledgeDeliver ViewState Zero-Day, Digital Knowledge LMS ViewState RCE, BLUEBEAM LMS Watering Hole
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
ZERO_DAY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
education, government, corporate-training, financial
Target regions
Japan, Asia-Pacific
Detection rules
9
Indicators of compromise
25

Malware and tooling in KnowledgeDeliver LMS ViewState Deserialization Zero-Day

Malware and tooling: BLUEBEAM, Godzilla, Cobalt Strike, icacls, ysoserial.net

How KnowledgeDeliver LMS ViewState Deserialization Zero-Day works

Mandiant disclosed CVE-2026-5426, an unauthenticated RCE in Digital Knowledge's KnowledgeDeliver Learning Management System (widely deployed in Japan). KnowledgeDeliver installations deployed before 2026-02-24 shipped with a vendor-supplied web.config that contained identical hardcoded ASP.NET machineKey decryptionKey/validationKey values across all customer environments. An attacker who obtains the shared key from any single instance can forge a signed/encrypted __VIEWSTATE payload and trigger arbitrary .NET deserialization on any internet-facing KnowledgeDeliver instance. The flaw was exploited as a zero-day in late 2025; post-exploitation included the in-memory BLUEBEAM (Godzilla) .NET web shell loaded inside w3wp.exe, icacls-based ACL relaxation of the webroot, tampering of an application JavaScript file to display a fake security plugin prompt, and watering-hole delivery of a Cobalt Strike BEACON whose per-victim AES key was derived from the targeted organization's name.

Overview

In late 2025, Mandiant responded to a compromise of an internet-facing web server running KnowledgeDeliver, a Learning Management System (LMS) developed by Tokyo-based Digital Knowledge Corporation and widely deployed at Japanese universities, training providers, and enterprise e-learning programs. The investigation identified a critical unauthenticated remote code execution vulnerability now tracked as CVE-2026-5426. The root cause is the use of identical pre-shared ASP.NET <machineKey> decryptionKey and validationKey values inside the vendor-supplied web.config that shipped with every KnowledgeDeliver installation deployed before 2026-02-24. Because every customer's IIS instance signed and encrypted ViewState (and forms-authentication tickets) with the same secret, an adversary who recovered the keys from any single deployment — or who obtained the standard vendor template — could forge a malicious __VIEWSTATE payload that any other internet-facing KnowledgeDeliver instance would accept and deserialize as trusted data, yielding unauthenticated SYSTEM-level code execution in the IIS worker process w3wp.exe.

Exploit Chain

1) Initial Access — The threat actor obtains the shared ASP.NET machineKey (decryptionKey + validationKey) from any KnowledgeDeliver instance or from the standardized vendor template. The actor then crafts a malicious ViewState blob using public tooling (for example ysoserial.net's TypeConfuseDelegate / TextFormattingRunProperties gadget chains) signed and encrypted with the shared keys. The payload is delivered as the __VIEWSTATE form field (or as a query/cookie value, depending on the page handler) to any ASPX page on the target KnowledgeDeliver instance. ASP.NET validates the MAC against the shared validationKey, decrypts with the shared decryptionKey, and deserializes the payload via LosFormatter / ObjectStateFormatter — executing the attacker-supplied gadget chain inside the w3wp.exe IIS worker process.

2) In-Memory Web Shell — Successful deserialization loads a .NET assembly named BLUEBEAM (the variant of the publicly known Godzilla web shell originally documented by Chinese-speaking researchers and re-reported by Microsoft in 2025 machine-key advisories). BLUEBEAM lives entirely inside the w3wp.exe process memory and never touches disk as a .aspx file, defeating file-based AV/EDR signatures. Operators interact with it by sending encrypted commands inside HTTP POST request bodies; responses are returned base64-encoded inside the HTTP response body. The Mandiant-recovered loader artifact LoadLibrary.dll (SHA-256 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2) is the BLUEBEAM payload.

3) Discovery, Defense Evasion, and Persistence — Operators issue reconnaissance commands through BLUEBEAM that surface as anomalous child processes of w3wp.exe: cmd.exe /c, whoami, powershell.exe. The actor uses icacls to grant the Everyone principal full access to the KnowledgeDeliver web root, ensuring later file-overwrite operations succeed regardless of the IIS application-pool identity's NTFS ACLs.

4) Watering-Hole / JavaScript Tampering — Rather than pivoting deeper into the LMS server, the actor weaponizes the compromised LMS as a strategic web compromise / watering hole against its legitimate users (students, staff, corporate trainees). One of the application's loaded JavaScript files is modified in place to (a) render a fake 'security authentication plugin' modal to the visitor and (b) silently fetch a second-stage attacker-hosted script. The remote loader convinces the user to download a fake installer.

5) Cobalt Strike BEACON Delivery — The fake installer drops and runs a Cobalt Strike BEACON loader. The BEACON shellcode is encrypted with an AES key derived from the targeted organization's name, indicating per-victim payload preparation and strong intent to evade cross-organization sample sharing. Mandiant reporting did not publish BEACON C2 infrastructure for this campaign.

Why This Vulnerability Is Critical

This is structurally identical to the broader ASP.NET 'publicly disclosed machineKey' problem class reported by Microsoft in 2025 and to the Sitecore CVE-2025-53690 ViewState zero-day, but with a supply-chain-equivalent blast radius: a single shared secret embedded in every customer deployment means a single key disclosure compromises every internet-facing installation simultaneously. Because the secret is delivered via the vendor's own install template, customers who never touched their web.config inherited the vulnerability silently. Affected sectors in Japan include higher education, vocational training, and corporate L&D programs that use KnowledgeDeliver as an internet-facing LMS.

Remediation Priorities

1) Generate a new cryptographically strong unique <machineKey> for each KnowledgeDeliver instance (aspnet_regiis -pc or the IIS Manager Machine Key feature) and restart IIS. This is the only mitigation that closes the vulnerability — patching the vendor template does not retroactively rotate already-deployed keys. 2) Restrict the LMS to known organizational IP ranges via firewall or reverse proxy ACLs while key rotation is performed. 3) Hunt Windows Application Event Log Event ID 1316 from source ASP.NET 4.0.30319.0 with 'Event code: 4009 Viewstate verification failed' messages — failed integrity checks are exploitation attempts with the wrong key; 'Viewstate was invalid' typically indicates a payload that passed integrity validation and reached deserialization. 4) Audit the LMS web root for unauthorized modifications to .js, .aspx, and .config files, with particular focus on injected remote-script loaders inside legitimate JavaScript bundles. 5) Treat any host that ever served as a KnowledgeDeliver LMS before 2026-02-24 as compromise-suspect and conduct full IR including process memory acquisition of w3wp.exe (in-memory web shells will not appear in disk scans).

MITRE ATT&CK techniques used in TL-2026-0577

Collection

T1005 Data from Local System

Discovery

T1033 System Owner/User Discovery; T1082 System Information Discovery

Defense Evasion

T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application

defense-impairment

T1222 File and Directory Permissions Modification

Impact

T1491 Defacement

Persistence

T1505 Server Software Component

Credential Access

T1552 Unsecured Credentials

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in KnowledgeDeliver LMS ViewState Deserialization Zero-Day

  • Digital Knowledge Corporation — KnowledgeDeliver (LMS)
    Vulnerable versions: All on-premises installations deployed before 2026-02-24 that use the vendor-supplied standardized web.config containing hardcoded ASP.NET machineKey
    Fixed in: Installations deployed on or after 2026-02-24 using the revised installer/configuration that generates unique per-instance machineKey values
  • Microsoft — ASP.NET / IIS
    Vulnerable versions: ASP.NET 4.x running KnowledgeDeliver with the vendor-shared machineKey (vulnerability is in the application's configuration, not in ASP.NET itself)

Remediation for KnowledgeDeliver LMS ViewState Deserialization Zero-Day

Patches

  • Apply Digital Knowledge KnowledgeDeliver vendor remediation for CVE-2026-5426 (revised installer / configuration guidance released 2026-02-24 — no longer ships hardcoded machineKey)
  • Patching alone is insufficient: existing deployments must additionally rotate machineKey because the previously shipped shared keys remain valid until rotated

Immediate actions

  • Rotate the ASP.NET machineKey to a unique, cryptographically strong decryptionKey + validationKey pair on every KnowledgeDeliver instance using aspnet_regiis -pc or IIS Manager Machine Key, then iisreset
  • Restrict KnowledgeDeliver LMS access to known organizational IP ranges via firewall, WAF, or reverse-proxy ACL while key rotation is performed
  • Hunt Windows Application Event Log Event ID 1316 from ASP.NET 4.0.30319.0 for 'Event code: 4009 Viewstate verification failed' messages across all KnowledgeDeliver IIS hosts (90+ day lookback)
  • Acquire process memory of w3wp.exe on every internet-facing KnowledgeDeliver host and scan for the BLUEBEAM/Godzilla .NET in-memory web shell
  • Audit and re-baseline every .js, .aspx, and .config file under the KnowledgeDeliver web root against a known-good vendor distribution; revert any unauthorized modifications and treat tampered JavaScript bundles as user-side watering-hole vectors

Workarounds

  • If immediate key rotation is not possible, take the KnowledgeDeliver instance offline or restrict it to a VPN-only network segment until rotation can be completed
  • Enable ViewStateUserKey on a per-user basis (Page.ViewStateUserKey = Session.SessionID) as a defense-in-depth measure — does not fully close the vulnerability but raises exploitation complexity
  • Block obviously anomalous concatenated User-Agent strings (two distinct browser identifiers concatenated together) at the WAF as a high-fidelity exploitation indicator

Longer-term hardening

  • Deploy EDR with .NET in-memory loader detection (e.g. AMSI for .NET 4.8+, behavioral detection of suspicious assembly loads inside w3wp.exe) to catch BLUEBEAM/Godzilla and similar in-memory web shells
  • Establish File Integrity Monitoring (FIM) on all IIS web roots covering .aspx, .ashx, .asmx, .ascx, .js, and .config files with alerting on unauthorized writes
  • Implement application-layer logging for IIS that records full request bodies and User-Agent strings to enable retrospective ViewState exploitation hunting
  • Adopt per-instance secret generation policy organization-wide; ban shared secrets in vendor deployment templates and require provisioning-time secret rotation
  • Segment internet-facing LMS, CMS, and other ASP.NET application servers from internal Active Directory, file shares, and developer endpoints to limit blast radius of an IIS worker compromise
  • Subscribe to vendor security mailing list and Digital Knowledge advisories; track KnowledgeDeliver patch status as part of monthly vulnerability management

CVEs associated with KnowledgeDeliver LMS ViewState Deserialization Zero-Day

CVE-2026-5426

Weaknesses (CWE) in KnowledgeDeliver LMS ViewState Deserialization Zero-Day

CWE-321, CWE-502, CWE-798, CWE-913

Timeline of KnowledgeDeliver LMS ViewState Deserialization Zero-Day

  • Threat actor began exploiting CVE-2026-5426 in the wild against internet-facing KnowledgeDeliver LMS instances as an unattributed zero-day (Mandiant case window: late 2025)
  • Mandiant engaged for incident response on a compromised KnowledgeDeliver web server; initial triage identified anomalous w3wp.exe child processes and ViewState verification failures in the Windows Application Event Log
  • Mandiant identified the BLUEBEAM in-memory .NET web shell loaded inside w3wp.exe and recovered the LoadLibrary.dll loader artifact (SHA-256 7c1f99dca...)
  • Mandiant coordinated disclosure with Digital Knowledge Corporation regarding the shared hardcoded ASP.NET machineKey in the vendor-supplied web.config template
  • Digital Knowledge released revised KnowledgeDeliver installer and configuration guidance that no longer ships hardcoded machineKey values; existing deployments must rotate keys manually
  • CVE-2026-5426 published in NVD with mandiant-cve@google.com as source identifier (CWE-321 Use of Hard-coded Cryptographic Key)
  • Threadlinqs Intelligence Platform created TL-2026-0577 to track CVE-2026-5426 exploitation; status set to ACTIVE pending broad customer key rotation across the KnowledgeDeliver install base
  • Google Threat Intelligence Group / Mandiant published full technical writeup documenting exploit chain, BLUEBEAM web shell, icacls ACL tampering, JavaScript watering-hole injection, and Cobalt Strike BEACON delivery
  • As of 2026-05-29, CVE-2026-5426 remains a live unauth RCE: the 2026-02-24 vendor installer fix does NOT close it, since shared/public machineKeys persist on pre-Feb-2026 KnowledgeDeliver installs until manually rotated, and the actor is uncaught. Mandiant's incident is contained, but exploit tooling is public and many legacy instances likely remain unrotated.

Sources cited for KnowledgeDeliver LMS ViewState Deserialization Zero-Day

Detection coverage for TL-2026-0577

As of 2026-05-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0577 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats