logo

U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14

ID: 9f4e2898-9b37-5259-b270-f4eac2c0ae87

STIX ID: report--9f4e2898-9b37-5259-b270-f4eac2c0ae87

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

Author: Pierluigi Paganini

...
...

CISA added Ivanti Sentry CVE-2026-10520 (CVSS 10.0), an unauthenticated OS command injection allowing root remote code execution, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 14, 2026. Researchers at Shadowserver reported active exploitation attempts and several internet-exposed Sentry instances backdoored shortly after patches were released, indicating real-world exploitation and high operational risk for organizations using Ivanti Sentry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.