www.securityweek.com 5/26/2026, 11:32:26 AM · external

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses the exploitation of a zero-day vulnerability (CVE-2026-5426) in the KnowledgeDeliver Learning Management System, widely used in Japan. Reported by Mandiant, the vulnerability arises from hardcoded values in the system's configuration, allowing attackers to perform ViewState deserialization attacks. The exploitation has led to the deployment of Godzilla web shells and a Cobalt Strike backdoor.

Organizations with KnowledgeDeliver deployments pre-February 24, 2026, are advised to rotate machine keys and monitor for intrusions. Mandiant has provided indicators of compromise (IoCs) related to this attack.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline