Security researchers report that a high-severity, now-patched vulnerability in the Digital Knowledge KnowledgeDeliver learning management system (LMS) is being used as a zero-day in active attacks. According to multiple accounts, attackers target a server running KnowledgeDeliver and exploit a flaw to gain the ability to install malicious web tooling.
The issue is identified as CVE-2026-5426, with a stated CVSS score of 7.5. The vulnerability is linked to the use of hard-coded ASP.NET machine keys, which can undermine the security of authentication and session handling. After successful exploitation, intruders deploy a Godzilla web shell on the compromised system, enabling further control.
Reports also state that the web shell is then used as a stepping stone to facilitate the deployment of additional malware, including Cobalt Strike Beacon. The exact mechanics of how the follow-on payload is delivered may vary between analyses, but both sources describe the same overall attack chain: exploitation of the KnowledgeDeliver flaw, installation of the Godzilla web shell, and subsequent deployment of Cobalt Strike.