CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 380

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry

Ivanti released security advisories for two critical vulnerabilities in Ivanti Sentry on June 9, 2026: CVE-2026-10520 (CVSS 10.0), an OS command injection enabling unauthenticated remote code execution as root, and CVE-2026-10523 (CVSS 9.9), an authentication bypass allowing creation of arbitrary administrative accounts. A public proof-of-concept exploit for CVE-2026-10520 was published on June 10, and the vulnerability was added to CISA's Known Exploited Vulnerabilities list on June 11 with evidence of active exploitation in the wild.

Why it matters: Both vulnerabilities are critical, unauthenticated, and actively exploited with public exploit code available; organizations running affected Ivanti Sentry versions should patch immediately outside normal maintenance windows.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry

Ivanti released security advisories for two critical vulnerabilities in Ivanti Sentry on June 9, 2026: CVE-2026-10520 (CVSS 10.0), an OS command injection enabling unauthenticated remote code execution as root, and CVE-2026-10523 (CVSS 9.9), an authentication bypass allowing creation of arbitrary administrative accounts. A public proof-of-concept exploit for CVE-2026-10520 was published on June 10, and the vulnerability was added to CISA's Known Exploited Vulnerabilities list on June 11 with evidence of active exploitation in the wild.

Why it matters: Both vulnerabilities are critical, unauthenticated, and actively exploited with public exploit code available; organizations running affected Ivanti Sentry versions should patch immediately outside normal maintenance windows.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary