Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5426

36
FAUCET Score

CVE-2026-5426 is a critical vulnerability affecting Digital Knowledge KnowledgeDeliver deployments released prior to February 24, 2026, stemming from a hard-coded ASP.NET/IIS machineKey value. This configuration flaw enables attackers to bypass ViewState validation protections and execute arbitrary code through malicious ViewState deserialization attacks. The vulnerability presents a high severity profile with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and results in high confidentiality impact, though integrity and availability impacts are not present. Currently, there is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention remains minimal as reflected by the low EPSS score of 0.00066. Organizations running affected versions should prioritize patching to the February 24, 2026 release or later, though the immediate exploitation risk appears contained at this time.

Impacted Technologies

VendorProductVersion(s)CPE
Digital KnowledgeKnowledgeDeliver
>= 0, < 20260224CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.01%
Probability of exploitation in next 30 days
EPSS Percentile
59.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0101 is in the 44th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cloud.google.com / blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability
github.com / mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0009.md
digital-knowledge.co.jp / product/kd