logo

Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10

ID: e18ad3ff-ad99-519a-a7ae-926fe7bdc44a

STIX ID: report--e18ad3ff-ad99-519a-a7ae-926fe7bdc44a

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

Critical Ivanti gateway vulnerabilities were disclosed: an unauthenticated root-level OS command injection (CVE-2026-10520, CVSS 10) and an authentication bypass allowing arbitrary admin account creation (CVE-2026-10523, CVSS 9.9). Public PoC code and analysis are available, vendors released urgent patches (10.5.2, 10.6.2, 10.7.1), and organizations are advised to apply updates and audit telemetry immediately; no in-the-wild exploitation was reported at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.