logo

Ivanti: Max severity Sentry flaw allows code execution as root

ID: e8f2d4d0-e686-5d8d-b6bc-32bf293f8187

STIX ID: report--e8f2d4d0-e686-5d8d-b6bc-32bf293f8187

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Sergiu Gatlan

...
...

Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway—CVE-2026-10520 (OS command injection allowing remote root code execution) and CVE-2026-10523 (remote authentication bypass enabling rogue admin account creation)—releasing Sentry versions R10.5.2, R10.6.2, and R10.7.1; the vendor reports no evidence of active exploitation but urges administrators to apply updates due to Ivanti's history of targeted zero-day attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.