U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
ID: 9f4e2898-9b37-5259-b270-f4eac2c0ae87
STIX ID: report--9f4e2898-9b37-5259-b270-f4eac2c0ae87
Feed Name: Security Affairs
CISA added Ivanti Sentry CVE-2026-10520 (CVSS 10.0), an unauthenticated OS command injection allowing root remote code execution, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 14, 2026. Researchers at Shadowserver reported active exploitation attempts and several internet-exposed Sentry instances backdoored shortly after patches were released, indicating real-world exploitation and high operational risk for organizations using Ivanti Sentry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
