logo

Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access

ID: 74fc4279-0afd-5413-a747-47b6b0df6332

STIX ID: report--74fc4279-0afd-5413-a747-47b6b0df6332

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

...
...

Ivanti released emergency patches on 2026-06-10 for two critical Sentry vulnerabilities — CVE-2026-10520 (unauthenticated OS command injection enabling root RCE, CVSS 10.0) and CVE-2026-10523 (authentication bypass allowing rogue admin account creation, CVSS 9.9) — affecting versions prior to R10.5.2/R10.6.2/R10.7.1; proof-of-concept code for the RCE is public, so immediate patching and monitoring are strongly advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.