# KnowledgeDeliver LMS ViewState Deserialization Zero-Day CVE-2026-5426 — Unauthenticated RCE via Shared ASP.NET machineKey + BLUEBEAM (Godzilla) Web Shell and Cobalt Strike BEACON Watering Hole

> Mandiant disclosed CVE-2026-5426, an unauthenticated RCE in Digital Knowledge's KnowledgeDeliver Learning Management System (widely deployed in Japan). KnowledgeDeliver installations deployed before 2026-02-24 shipped with a vendor-supplied web.config that contained identical hardcoded ASP.NET machineKey decryptionKey/validationKey values across all customer environments. An attacker who obtains the shared key from any single instance can forge a signed/encrypted __VIEWSTATE payload and trigger arbitrary .NET deserialization on any internet-facing KnowledgeDeliver instance. The flaw was exploited as a zero-day in late 2025; post-exploitation included the in-memory BLUEBEAM (Godzilla) .NET web shell loaded inside w3wp.exe, icacls-based ACL relaxation of the webroot, tampering of an application JavaScript file to display a fake security plugin prompt, and watering-hole delivery of a Cobalt Strike BEACON whose per-victim AES key was derived from the targeted organization's name.

- **Published:** 2026-05-25T00:00:00Z
- **Last reviewed:** 2026-05-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0577
- **ID:** TL-2026-0577
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** ZERO_DAY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-5426

## Description

Overview

In late 2025, Mandiant responded to a compromise of an internet-facing web server running KnowledgeDeliver, a Learning Management System (LMS) developed by Tokyo-based Digital Knowledge Corporation and widely deployed at Japanese universities, training providers, and enterprise e-learning programs. The investigation identified a critical unauthenticated remote code execution vulnerability now tracked as CVE-2026-5426. The root cause is the use of identical pre-shared ASP.NET <machineKey> decryptionKey and validationKey values inside the vendor-supplied web.config that shipped with every KnowledgeDeliver installation deployed before 2026-02-24. Because every customer's IIS instance signed and encrypted ViewState (and forms-authentication tickets) with the same secret, an adversary who recovered the keys from any single deployment — or who obtained the standard vendor template — could forge a malicious __VIEWSTATE payload that any other internet-facing KnowledgeDeliver instance would accept and deserialize as trusted data, yielding unauthenticated SYSTEM-level code execution in the IIS worker process w3wp.exe.

Exploit Chain

1) Initial Access — The threat actor obtains the shared ASP.NET machineKey (decryptionKey + validationKey) from any KnowledgeDeliver instance or from the standardized vendor template. The actor then crafts a malicious ViewState blob using public tooling (for example ysoserial.net's TypeConfuseDelegate / TextFormattingRunProperties gadget chains) signed and encrypted with the shared keys. The payload is delivered as the __VIEWSTATE form field (or as a query/cookie value, depending on the page handler) to any ASPX page on the target KnowledgeDeliver instance. ASP.NET validates the MAC against the shared validationKey, decrypts with the shared decryptionKey, and deserializes the payload via LosFormatter / ObjectStateFormatter — executing the attacker-supplied gadget chain inside the w3wp.exe IIS worker process.

2) In-Memory Web Shell — Successful deserialization loads a .NET assembly named BLUEBEAM (the variant of the publicly known Godzilla web shell originally documented by Chinese-speaking researchers and re-reported by Microsoft in 2025 machine-key advisories). BLUEBEAM lives entirely inside the w3wp.exe process memory and never touches disk as a .aspx file, defeating file-based AV/EDR signatures. Operators interact with it by sending encrypted commands inside HTTP POST request bodies; responses are returned base64-encoded inside the HTTP response body. The Mandiant-recovered loader artifact LoadLibrary.dll (SHA-256 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2) is the BLUEBEAM payload.

3) Discovery, Defense Evasion, and Persistence — Operators issue reconnaissance commands through BLUEBEAM that surface as anomalous child processes of w3wp.exe: cmd.exe /c, whoami, powershell.exe. The actor uses icacls to grant the Everyone principal full access to the KnowledgeDeliver web root, ensuring later file-overwrite operations succeed regardless of the IIS application-pool identity's NTFS ACLs.

4) Watering-Hole / JavaScript Tampering — Rather than pivoting deeper into the LMS server, the actor weaponizes the compromised LMS as a strategic web compromise / watering hole against its legitimate users (students, staff, corporate trainees). One of the application's loaded JavaScript files is modified in place to (a) render a fake 'security authentication plugin' modal to the visitor and (b) silently fetch a second-stage attacker-hosted script. The remote loader convinces the user to download a fake installer.

5) Cobalt Strike BEACON Delivery — The fake installer drops and runs a Cobalt Strike BEACON loader. The BEACON shellcode is encrypted with an AES key derived from the targeted organization's name, indicating per-victim payload preparation and strong intent to evade cross-organization sample sharing. Mandiant reporting did not publish BEACON C2 infrastructure for this campaign.

Why This Vulnerability Is Critical

This is structurally identical to the broader ASP.NET 'publicly disclosed machineKey' problem class reported by Microsoft in 2025 and to the Sitecore CVE-2025-53690 ViewState zero-day, but with a supply-chain-equivalent blast radius: a single shared secret embedded in every customer deployment means a single key disclosure compromises every internet-facing installation simultaneously. Because the secret is delivered via the vendor's own install template, customers who never touched their web.config inherited the vulnerability silently. Affected sectors in Japan include higher education, vocational training, and corporate L&D programs that use KnowledgeDeliver as an internet-facing LMS.

Remediation Priorities

1) Generate a new cryptographically strong unique <machineKey> for each KnowledgeDeliver instance (aspnet_regiis -pc or the IIS Manager Machine Key feature) and restart IIS. This is the only mitigation that closes the vulnerability — patching the vendor template does not retroactively rotate already-deployed keys. 2) Restrict the LMS to known organizational IP ranges via firewall or reverse proxy ACLs while key rotation is performed. 3) Hunt Windows Application Event Log Event ID 1316 from source ASP.NET 4.0.30319.0 with 'Event code: 4009 Viewstate verification failed' messages — failed integrity checks are exploitation attempts with the wrong key; 'Viewstate was invalid' typically indicates a payload that passed integrity validation and reached deserialization. 4) Audit the LMS web root for unauthorized modifications to .js, .aspx, and .config files, with particular focus on injected remote-script loaders inside legitimate JavaScript bundles. 5) Treat any host that ever served as a KnowledgeDeliver LMS before 2026-02-24 as compromise-suspect and conduct full IR including process memory acquisition of w3wp.exe (in-memory web shells will not appear in disk scans).

## MITRE ATT&CK

- T1595 Active Scanning
- T1596 Search Open Technical Databases
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1608 Stage Capabilities
- T1190 Exploit Public-Facing Application
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1505 Server Software Component
- T1222 File and Directory Permissions Modification
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1055 Process Injection
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1033 System Owner/User Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1491 Defacement

## Sources

- [Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability (Mandiant / Google Threat Intelligence)](https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/)
- [NVD entry CVE-2026-5426](https://nvd.nist.gov/vuln/detail/CVE-2026-5426)
- [Digital Knowledge KnowledgeDeliver Product Page](https://www.digital-knowledge.co.jp/products/knowledgedeliver/)
- [Sitecore ViewState Deserialization Zero-Day (CVE-2025-53690) — prior art for same exploitation pattern (Mandiant)](https://cloud.google.com/blog/topics/threat-intelligence/sitecore-viewstate-deserialization-zero-day-vulnerability/)
- [Code injection attacks using publicly disclosed ASP.NET machine keys (Microsoft Security)](https://www.microsoft.com/en-us/security/blog/2025/02/06/code-injection-attacks-using-publicly-disclosed-asp-net-machine-keys/)
- [CWE-321: Use of Hard-coded Cryptographic Key](https://cwe.mitre.org/data/definitions/321.html)
- [CWE-502: Deserialization of Untrusted Data](https://cwe.mitre.org/data/definitions/502.html)
- [ysoserial.net — .NET deserialization gadget generator (public PoC class used to weaponize ViewState)](https://github.com/pwntester/ysoserial.net)
- [MITRE ATT&CK T1190 — Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/)
- [MITRE ATT&CK T1505.003 — Web Shell](https://attack.mitre.org/techniques/T1505/003/)
- [Microsoft Docs — IIS <machineKey> Element Reference](https://learn.microsoft.com/en-us/iis/configuration/system.web/machinekey/)
- [Google SecOps detection rules: ASP.NET ViewState Deserialization Attempt, W3wp Launching Cmd With Recon Commands, IIS ViewState Exploitation Success (Mandiant Hunting Rules / Frontline Threats packs)](https://cloud.google.com/security/products/security-operations)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0577
