Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)
ID: af8bc5b3-fbd1-54e3-8778-ffa34160ed46
STIX ID: report--af8bc5b3-fbd1-54e3-8778-ffa34160ed46
Feed Name: Help Net Security
Threat Score
Ivanti patched two critical vulnerabilities in Ivanti Sentry (CVE-2026-10520: unauthenticated OS command injection enabling root RCE; CVE-2026-10523: authentication bypass allowing creation of admin accounts). Both affect multiple pre-10.5.2/10.6.2/10.7.1 versions, are internet-reachable in typical deployments, and—while not yet observed in the wild—public technical details and a detection script have been released, so customers are urged to apply fixes immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
