www.rapid7.com 10 Jun 2026, 10:21 UTC

CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry

CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
CyberSIXT Evidence Panel
Primary Source hub.ivanti.com
CISA KEV Listed in KEV
Patch Patch Available

THE content discusses the critical vulnerabilities CVE-2026-10520 and CVE-2026-10523 affecting Ivanti Sentry. CVE-2026-10520 is an OS command injection vulnerability (CVSS score 10.0) allowing remote code execution, while CVE-2026-10523 is an authentication bypass vulnerability (CVSS score 9.9) that lets unauthenticated attackers create administrative accounts. Ivanti has released a security advisory, but no exploitation has been reported so far.

Organizations using affected versions (10.7.0 and below) are urged to apply the vendor-supplied updates (10.7.1 and above) immediately due to the critical severity and availability of proof-of-concept exploits. Rapid7 customers can use vulnerability checks from June 11 to assess their exposure.

View Primary Source Via www.rapid7.com

Article by CyberSIXT