CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 559

As cited

Copy frozen at (site build).

vulnerabilities

More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)

Ivanti released an advisory for two critical vulnerabilities in its Sentry product: CVE-2026-10520, a pre-authenticated OS command injection flaw allowing unauthenticated remote code execution with CVSS 10.0, and CVE-2026-10523, an authentication bypass enabling creation of arbitrary administrative accounts. Both vulnerabilities affect Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1.

Why it matters: Organizations running vulnerable Ivanti Sentry versions face immediate risk of complete system compromise through unauthenticated remote code execution and administrative account creation, requiring urgent patching or network segmentation to prevent in-the-wild exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)

Ivanti released an advisory for two critical vulnerabilities in its Sentry product: CVE-2026-10520, a pre-authenticated OS command injection flaw allowing unauthenticated remote code execution with CVSS 10.0, and CVE-2026-10523, an authentication bypass enabling creation of arbitrary administrative accounts. Both vulnerabilities affect Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1.

Why it matters: Organizations running vulnerable Ivanti Sentry versions face immediate risk of complete system compromise through unauthenticated remote code execution and administrative account creation, requiring urgent patching or network segmentation to prevent in-the-wild exploitation.

VendorsMicrosoftIvantiOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary