Bleepingcomputer
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Article Content
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root privileges, rated 10.0 on the CVSS scale. The second, CVE-2026-10523, is an authentication bypass vulnerability enabling unauthenticated attackers to create rogue administrative accounts, rated 9.9. Both vulnerabilities were disclosed on June 9, 2026, and patches were released on June 10, 2026, with no evidence of active exploitation reported at that time. However, researchers have already published proof-of-concept exploits, increasing the urgency for organizations to apply the patches. The vulnerabilities affect Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. Given the critical nature of these flaws, immediate action is recommended to mitigate potential risks.
Key Points: • CVE-2026-10520 allows remote code execution with root privileges, rated CVSS 10.0. • CVE-2026-10523 enables unauthenticated attackers to create rogue admin accounts, rated CVSS 9.9. • Patches are available for affected Ivanti Sentry versions; immediate upgrading is advised.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.