Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Over 400 Arch Linux packages compromised to push rootkit, infostealer

    June 13, 2026

    Chinese hackers hijack auth flow, spy on isolated network for a decade

    June 13, 2026

    Ukrainian national pleads guilty to role in Conti ransomware operation

    June 13, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Max severity Sentry flaw allows code execution as root
    News

    Max severity Sentry flaw allows code execution as root

    adminBy adminJune 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ivanti

    Security software company Ivanti has released patches to address two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges.

    Formerly known as MobileIron Sentry, Ivanti Sentry is a security gateway appliance that secures traffic between back-end corporate systems and remote mobile devices.

    Tracked as CVE-2026-10520, the maximum-severity vulnerability stems from an OS command injection weakness. The second Sentry security flaw patched on Tuesday (tracked as CVE-2026-10523) is a critical authentication bypass that can be exploited remotely by unauthenticated attackers to create rogue administrative accounts and gain full administrative access.

    image

    Ivanti patched both security issues on Tuesday with the release of Sentry versions R10.5.2, R10.6.2, and R10.7.1.

    Luckily, the company said it has no evidence that the two vulnerabilities are being exploited in the wild and advised admins to upgrade their systems to protect against potential attacks.

    “We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure,” Ivanti said. “Currently, there is no known public exploitation of this vulnerability that could be used to provide a list of indicators of compromise.”

    In recent years, Ivanti vulnerabilities have often been targeted in attacks because they provide an easy way for cybercriminals to breach targets’ enterprise networks and steal sensitive corporate and customer data.

    For instance, most recently, the Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies in May to patch their Ivanti devices after the company warned customers to immediately patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) that was exploited in zero-day attacks.

    Multiple other Ivanti zero-days have been exploited in recent years to breach a wide range of targets, including government agencies worldwide, including two other critical EPMM vulnerabilities addressed by Ivanti in January after being exploited as zero-days in attacks against a “very limited number of customers.”

    In total, CISA has tagged 34 vulnerabilities across various SolarWinds products as actively exploited in attacks over the past several years, with 12 of them also used in ransomware attacks.

    Ivanti’s IT asset management solutions are used by over 40,000 clients worldwide and are supported by a network of over 7,000 partners and over 3,000 employees.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSecond-Order OS Command Injection via JSON Input on start vnc feature
    Next Article ZDI-26-340: Progress Software Kemp LoadMaster dodelapikey Uninitialized Memory Remote Code Execution Vulnerability
    admin
    • Website

    Related Posts

    News

    Over 400 Arch Linux packages compromised to push rootkit, infostealer

    June 13, 2026
    News

    Chinese hackers hijack auth flow, spy on isolated network for a decade

    June 13, 2026
    News

    Ukrainian national pleads guilty to role in Conti ransomware operation

    June 13, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202632 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202632 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    Over 400 Arch Linux packages compromised to push rootkit, infostealer

    June 13, 2026

    Chinese hackers hijack auth flow, spy on isolated network for a decade

    June 13, 2026

    Ukrainian national pleads guilty to role in Conti ransomware operation

    June 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.