logo

Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure

ID: f5e07adc-ba89-533e-9b50-64f1b6e6464f

STIX ID: report--f5e07adc-ba89-533e-9b50-64f1b6e6464f

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-15

Author: Rob Wright

...
...

Ivanti disclosed a critical OS command injection vulnerability (CVE-2026-10520, CVSS 10) in its Sentry gateway; a public PoC quickly appeared and threat actors began exploiting it within 24 hours, with multiple instances observed being probed and at least two backdoored. Security vendors and observers reported widespread, automated exploitation including direct attacks on honeypots, and warned that compromise of Sentry appliances can expose credentials, configurations, and enable lateral movement — prompting an urgent call to patch affected versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.