Critical Ivanti Sentry Flaws Allow Unauthenticated RCE
Ivanti has disclosed two critical vulnerabilities in Ivanti Sentry—CVE-2026-10520 and CVE-2026-10523—that enable unauthenticated attackers to achieve remote code execution (RCE). CVE-2026-10520 is an authentication bypass vulnerability with a CVSS score of 9.8, while CVE-2026-10523 is a command inje