Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
ID: f5e07adc-ba89-533e-9b50-64f1b6e6464f
STIX ID: report--f5e07adc-ba89-533e-9b50-64f1b6e6464f
Feed Name: Dark Reading
Ivanti disclosed a critical OS command injection vulnerability (CVE-2026-10520, CVSS 10) in its Sentry gateway; a public PoC quickly appeared and threat actors began exploiting it within 24 hours, with multiple instances observed being probed and at least two backdoored. Security vendors and observers reported widespread, automated exploitation including direct attacks on honeypots, and warned that compromise of Sentry appliances can expose credentials, configurations, and enable lateral movement — prompting an urgent call to patch affected versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
