Bleepingcomputer
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root privileges, rated 10.0 on the CVSS scale. The second, CVE-2026-10523, is an authentication bypass vulnerability enabling unauthenticated attackers to create rogue administrative accounts, rated 9.9. Both vulnerabilities were disclosed on June 9, 2026, and patches were released on June 10, 2026, with no evidence of active exploitation reported at that time. However, researchers have already published proof-of-concept exploits, increasing the urgency for organizations to apply the patches. The vulnerabilities affect Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. Given the critical nature of these flaws, immediate action is recommended to mitigate potential risks.
Key Points: • CVE-2026-10520 allows remote code execution with root privileges, rated CVSS 10.0. • CVE-2026-10523 enables unauthenticated attackers to create rogue admin accounts, rated CVSS 9.9. • Patches are available for affected Ivanti Sentry versions; immediate upgrading is advised.