Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
ID: 74fc4279-0afd-5413-a747-47b6b0df6332
STIX ID: report--74fc4279-0afd-5413-a747-47b6b0df6332
Feed Name: ThreatCluster
Threat Score
Ivanti released emergency patches on 2026-06-10 for two critical Sentry vulnerabilities — CVE-2026-10520 (unauthenticated OS command injection enabling root RCE, CVSS 10.0) and CVE-2026-10523 (authentication bypass allowing rogue admin account creation, CVSS 9.9) — affecting versions prior to R10.5.2/R10.6.2/R10.7.1; proof-of-concept code for the RCE is public, so immediate patching and monitoring are strongly advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
