KnowledgeDeliver flaw exploited as a zero-day to install web shells | HappeningNow.news

Cybersecurity · 55 views

KnowledgeDeliver flaw exploited as a zero-day to install web shells

Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.

Source AI Summary Published May 26, 2026 Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 55 Community interest
Brief read Under 1 min brief 70 words

AI Summary

Hackers used a critical zero‑day vulnerability in the KnowledgeDeliver learning management system to install the Godzilla web shell on a server. The flaw, a deserialization issue identified as CVE‑2026‑5426, can be exploited without authentication. It originates from the use of a shared hardcoded machine key in the web portal configuration that is common to all KnowledgeDeliver customer deployments. The attack allows remote code execution and persistence on the affected server.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at Bleepingcomputer

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page