Portsuppe

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Mandiant Blog·5d·Reputable

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform,

Categories cybersecurity · government-security · unknown-it-category-15
Original source / advisory
Published
5/25/2026, 2:00:00 PM
Fetched
5/30/2026, 12:53:42 AM
Trust
reputable · 80/100
Language
en