Briefing

CVE‑2026‑5426: Hard‑Coded ASP.NET Keys in KnowledgeDeliver Enable Godzilla Shell

security
by [email protected] (The Hacker News) · CVE-2026-5426

Patch Digital Knowledge KnowledgeDeliver to fix hard‑coded ASP.NET machine keys and prevent Godzilla shell exploitation.

What to do now

Apply the official patch for KnowledgeDeliver immediately to eliminate the hard‑coded key vulnerability.

Summary

A now‑patched high‑severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System popular in Japan, was exploited as a zero‑day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE‑2026‑5426 with a CVSS score of 7.5, stems from the use of hard‑coded ASP.NET machine keys. Attackers leveraged the flaw to gain remote code execution and install malicious backdoors. The flaw was patched after exploitation was discovered, but the zero‑day impact was significant. KnowledgeDeliver users in Japan were at risk of remote compromise. The incident underscores the importance of secure key management in web applications. Immediate patching is required to eliminate the vulnerability.

Key changes

  • CVE‑2026‑5426 high‑severity flaw in KnowledgeDeliver
  • Exploited to deliver Godzilla web shell
  • Enables Cobalt Strike Beacon deployment
  • Root cause: hard‑coded ASP.NET machine keys
  • Patch now available
  • Affected LMS popular in Japan

Affects

enterprise internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting