Ivanti: Max severity Sentry flaw allows code execution as root
ID: e8f2d4d0-e686-5d8d-b6bc-32bf293f8187
STIX ID: report--e8f2d4d0-e686-5d8d-b6bc-32bf293f8187
Feed Name: Bleeping Computer
Threat Score
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway—CVE-2026-10520 (OS command injection allowing remote root code execution) and CVE-2026-10523 (remote authentication bypass enabling rogue admin account creation)—releasing Sentry versions R10.5.2, R10.6.2, and R10.7.1; the vendor reports no evidence of active exploitation but urges administrators to apply updates due to Ivanti's history of targeted zero-day attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
