logo

2026-008: Critical vulnerabilities in Ivanti Sentry

ID: dbdda451-f282-507b-87e2-635d47aba4c7

STIX ID: report--dbdda451-f282-507b-87e2-635d47aba4c7

Feed Name: CERT-EU Security Advisories

Threat Score
90/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

...
...

Ivanti published a security advisory on 9 June 2026 for Ivanti Sentry detailing two critical vulnerabilities: CVE-2026-10520 (unauthenticated OS command injection, CVSS 10) enabling root remote code execution, and CVE-2026-10523 (authentication bypass, CVSS 9.9) enabling creation of arbitrary admin accounts; affected versions include 10.5.1 and prior, 10.6.1 and prior, and 10.7.0 and prior, and CERT-EU recommends updating to the fixed versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.