2026-008: Critical vulnerabilities in Ivanti Sentry
Cybersecurity Classified by Officially
Critical vulnerabilities in Ivanti Sentry
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
The vulnerability CVE-2026-10520, with a CVSS score of 10, is an OS Command Injection vulnerability in Ivanti Sentry which allows a remote unauthenticated user to achieve root-level remote code execution[2].
The vulnerability CVE-2026-10523, with a CVSS score of 9.9, is an Authentication Bypass vulnerability in Ivanti Sentry which allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.
The following versions of Ivanti Sentry are affected:
CERT-EU recommends following the vendor's guidance to update their appliance to one of the fixed versions[1].
This is an extract. The publication continues at the source.
Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-008/
Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT-EU — imported from official source
- Official source
- https://www.cert.europa.eu/publications/security-advisories-rss RSS
- Imported
- September 15, 2026 20:57
- Versions
- 1 recorded
- Identity
security-advisories-10945