CVE-2026-10520 is a vulnerability tracked across 2 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed June 10, 2026; most recent activity July 2, 2026.
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…