Critical Vulnerabilities in Ivanti Sentry
ID: 49b9a80c-474f-53b5-ad78-9557b3f6453d
STIX ID: report--49b9a80c-474f-53b5-ad78-9557b3f6453d
Feed Name: Kudelski Security
Two critical unauthenticated vulnerabilities in Ivanti Sentry (CVE-2026-10520 and CVE-2026-10523) allow remote attackers to achieve root remote code execution and to create arbitrary administrative accounts; affected releases are versions prior to R10.5.2, R10.6.2, and R10.7.1. The advisory identifies the vulnerable API endpoint (/mics/api/v2/sentry/mics-config/handleMessage), describes exploitation mechanics and monitoring indicators, and urges immediate upgrades to fixed versions, restricting external access, and reviewing systems for compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
