2026-008: Critical vulnerabilities in Ivanti Sentry
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Ivanti
- Reported by
- 1 outlet
History:
- 10/06/2026 --- v1.0 -- Initial publication
Summary
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
Technical Details
The vulnerability CVE-2026-10520, with a CVSS score of 10, is an OS Command Injection vulnerability in Ivanti Sentry which allows a remote unauthenticated user to achieve root-level remote code execution[2].
The vulnerability CVE-2026-10523, with a CVSS score of 9.9, is an Authentication Bypass vulnerability in Ivanti Sentry which allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.
Affected Products
The following versions of Ivanti Sentry are affected:
- 10.5.1 and prior.
- 10.6.1 and prior.
- 10.7.0 and prior.
Recommendations
CERT-EU recommends following the vendor's guidance to update their appliance to one of the fixed versions[1].
References
[1] https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523
Reproduced in full under licence from CERT-EU. © CERT-EU.
Coverage
One outlet has carried this so far.
time not given by source
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited