KnowledgeDeliver LMS Hard-Coded Keys RCE | MSSP Advisory
High
DateMay 26, 2026
📋Executive Summary
A high-severity vulnerability in Digital Knowledge KnowledgeDeliver Learning Management System was exploited as a zero-day to deploy Godzilla web shells and Cobalt Strike Beacon. The flaw stems from hard-coded ASP.NET machine keys that allow attackers to achieve remote code execution on affected systems. This LMS platform is popular in Japan and the vulnerability has been patched.
⚠️Why It Matters for MSSPs
Your clients running any LMS platforms face similar risks from hard-coded credentials and poor authentication implementations that create backdoor access for attackers. Once web shells are planted, attackers gain persistent access to move laterally through client networks and deploy post-exploitation tools like Cobalt Strike. The zero-day exploitation window means traditional signature-based detection missed the initial compromise.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.