2026-008: Critical vulnerabilities in Ivanti Sentry
ID: dbdda451-f282-507b-87e2-635d47aba4c7
STIX ID: report--dbdda451-f282-507b-87e2-635d47aba4c7
Feed Name: CERT-EU Security Advisories
Threat Score
Ivanti published a security advisory on 9 June 2026 for Ivanti Sentry detailing two critical vulnerabilities: CVE-2026-10520 (unauthenticated OS command injection, CVSS 10) enabling root remote code execution, and CVE-2026-10523 (authentication bypass, CVSS 9.9) enabling creation of arbitrary admin accounts; affected versions include 10.5.1 and prior, 10.6.1 and prior, and 10.7.0 and prior, and CERT-EU recommends updating to the fixed versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
