Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9
ID: 13446984-b075-5aa8-a7cb-776f427ad79e
STIX ID: report--13446984-b075-5aa8-a7cb-776f427ad79e
Feed Name: The Register (Security)
Ivanti disclosed two critical vulnerabilities in its Sentry mobile gateway: CVE-2026-10520 (CVSS 10.0) enables remote, unauthenticated code execution as root via an exposed Tomcat-backed API, and CVE-2026-10523 (CVSS 9.9) permits authentication bypass to create admin accounts; customers are advised to upgrade to patched versions (10.5.2, 10.6.2, or 10.7.1). Vendor reports no confirmed exploitation in the wild, but public disclosures and researcher analyses provide clues that could be used to attack unpatched systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
