<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

KnowledgeDeliver LMS Zero-Day Used to Deploy Stealthy In-Memory Web Shell

Explore the critical CVE-2026-5426 flaw in KnowledgeDeliver LMS exploited for remote attacks, urging immediate machine key updates.
Content Team

A zero-day flaw in Digital Knowledge's KnowledgeDeliver LMS (CVE-2026-5426, CVSS 9.1 Critical) was exploited in late 2025 to deploy BLUEBEAM — a .NET in-memory web shell also tracked as Godzilla — which runs inside the IIS worker process and leaves few on-disk artifacts. Mandiant, responding to the intrusion, traced it to identical hardcoded ASP.NET machine keys shipped across customer installations.

Anyone holding that key could forge ViewState payloads and run code with no authentication, provided the LMS was reachable from the internet. Once in, the attacker used icacls to grant broad access to the web directory, tampered with legitimate JavaScript to display a fake security alert, and pushed a Cobalt Strike Beacon to users who installed the bogus plugin.

Digital Knowledge changed its deployment procedure on February 24, 2026 so new installations get unique keys — but that does nothing for anything provisioned earlier. If yours predates that date, generate a unique, cryptographically strong machineKey now, restrict access to known IP ranges, and hunt backwards: ASP.NET Event ID 1316, and cmd.exe or powershell.exe spawning from w3wp.exe, are the tells.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo