<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Ivanti Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Ivanti.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push</title><link>https://darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation</link><guid isPermaLink="false">cst-2873</guid><description>Ivanti's Chief Security Officer reports that large language models show promise in early testing for vulnerability remediation automation, though questions persist about cost-effectiveness and the need for human oversight. The company is exploring frontier models to streamline the patching process, balancing efficiency gains with practical deployment constraints.</description><pubDate>Mon, 20 Jul 2026 20:26:56 GMT</pubDate></item><item><title>Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow</title><link>https://securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow</link><guid isPermaLink="false">cst-2576</guid><description>ServiceNow, Fortinet, and Ivanti each released patches for security vulnerabilities affecting their platforms. A critical vulnerability in ServiceNow's AI platform could allow remote attackers to execute arbitrary code.</description><pubDate>Wed, 15 Jul 2026 11:02:57 GMT</pubDate></item><item><title>Microsoft releases Windows 10 KB5099539 extended security update</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update</link><guid isPermaLink="false">cst-2513</guid><description>Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.</description><pubDate>Tue, 14 Jul 2026 18:49:28 GMT</pubDate></item><item><title>CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry</title><link>https://rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry</link><guid isPermaLink="false">cst-380</guid><description>Ivanti released security advisories for two critical vulnerabilities in Ivanti Sentry on June 9, 2026: CVE-2026-10520 (CVSS 10.0), an OS command injection enabling unauthenticated remote code execution as root, and CVE-2026-10523 (CVSS 9.9), an authentication bypass allowing creation of arbitrary administrative accounts. A public proof-of-concept exploit for CVE-2026-10520 was published on June 10, and the vulnerability was added to CISA's Known Exploited Vulnerabilities list on June 11 with evidence of active exploitation in the wild.</description><pubDate>Wed, 10 Jun 2026 10:21:07 GMT</pubDate></item><item><title>More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)</title><link>https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520</link><guid isPermaLink="false">cst-559</guid><description>Ivanti released an advisory for two critical vulnerabilities in its Sentry product: CVE-2026-10520, a pre-authenticated OS command injection flaw allowing unauthenticated remote code execution with CVSS 10.0, and CVE-2026-10523, an authentication bypass enabling creation of arbitrary administrative accounts. Both vulnerabilities affect Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1.</description><pubDate>Wed, 10 Jun 2026 00:52:20 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)</title><link>https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains</link><guid isPermaLink="false">cst-563</guid><description>watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.</description><pubDate>Wed, 18 Mar 2026 10:02:49 GMT</pubDate></item><item><title>Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere</title><link>https://greynoise.io/blog/active-ivanti-exploitation</link><guid isPermaLink="false">cst-1860</guid><description>GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.</description><pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 &amp; CVE-2026-1340)</title><link>https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340</link><guid isPermaLink="false">cst-566</guid><description>Ivanti released patches for two pre-authentication remote code execution vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (EPMM), an enterprise mobility management platform used to control corporate mobile devices. The vulnerabilities are actively exploited in the wild and have been added to CISA's Known Exploited Vulnerabilities list. Permanent patches are not available until Q1 2026; customers are currently receiving temporary RPM patches that must be reapplied after system updates to remain effective.</description><pubDate>Fri, 30 Jan 2026 16:15:16 GMT</pubDate></item><item><title>Ivanti EPMM Zero-Days: Reconnaissance to Exploitation</title><link>https://greynoise.io/blog/ivanti-epmm-zero-days-reconnaissance-exploitation</link><guid isPermaLink="false">cst-1902</guid><description>Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2025-4427 and CVE-2025-4428) are under active exploitation following increased reconnaissance scanning activity. When chained together, these flaws allow unauthenticated remote code execution on affected systems.</description><pubDate>Fri, 16 May 2025 00:00:00 GMT</pubDate></item><item><title>9X Surge in Ivanti Connect Secure Scanning Activity</title><link>https://greynoise.io/blog/surge-ivanti-connect-secure-scanning-activity</link><guid isPermaLink="false">cst-1905</guid><description>GreyNoise detected a nine-fold increase in suspicious scanning activity targeting Ivanti Connect Secure and Ivanti Pulse Secure VPN systems, with more than 230 unique IP addresses conducting probes against these endpoints. The surge in reconnaissance activity suggests possible coordinated preparation for future exploitation attacks.</description><pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Heightened In-The-Wild Activity On Key Technologies Observed On March 28</title><link>https://greynoise.io/blog/heightened-in-the-wild-activity-key-technologies</link><guid isPermaLink="false">cst-1908</guid><description>On March 28, GreyNoise detected a sharp increase in wild exploitation activity targeting multiple vendors including SonicWall, Zoho, Zyxel, F5, Linksys, and Ivanti. The affected technologies span both edge systems and internal management tools, suggesting a broad attack campaign.</description><pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate></item><item><title>CVE-2025-0282 and CVE-2025-0283: Critical Ivanti 0days Exploited in the Wild</title><link>https://wiz.io/blog/cve-2025-0282-and-cve-2025-0283-critical-ivanti-0days-exploited-in-the-wild</link><guid isPermaLink="false">cst-1507</guid><description>Ivanti has disclosed two critical remote code execution (RCE) vulnerabilities in Connect Secure, identified as CVE-2025-0282 and CVE-2025-0283, that are being actively exploited in the wild. Organizations using these products require immediate patching to prevent compromise.</description><pubDate>Thu, 09 Jan 2025 14:23:44 GMT</pubDate></item></channel></rss>