2026-008: Critical vulnerabilities in Ivanti Sentry

Imported from official source

Advisory

Cybersecurity Classified by Officially

Critical vulnerabilities in Ivanti Sentry

  • 10/06/2026 --- v1.0 -- Initial publication
  • On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.

    The vulnerability CVE-2026-10520, with a CVSS score of 10, is an OS Command Injection vulnerability in Ivanti Sentry which allows a remote unauthenticated user to achieve root-level remote code execution[2].

    The vulnerability CVE-2026-10523, with a CVSS score of 9.9, is an Authentication Bypass vulnerability in Ivanti Sentry which allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.

    The following versions of Ivanti Sentry are affected:

    CERT-EU recommends following the vendor's guidance to update their appliance to one of the fixed versions[1].

    This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-008/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    1 recorded
    Identity
    security-advisories-10945

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.