logo

Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)

ID: af8bc5b3-fbd1-54e3-8778-ffa34160ed46

STIX ID: report--af8bc5b3-fbd1-54e3-8778-ffa34160ed46

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Zeljka Zorz

...
...

Ivanti patched two critical vulnerabilities in Ivanti Sentry (CVE-2026-10520: unauthenticated OS command injection enabling root RCE; CVE-2026-10523: authentication bypass allowing creation of admin accounts). Both affect multiple pre-10.5.2/10.6.2/10.7.1 versions, are internet-reachable in typical deployments, and—while not yet observed in the wild—public technical details and a detection script have been released, so customers are urged to apply fixes immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.