Critical severity9.9NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-10523
CVE-2026-10523
Description
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
10- Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHelp Net Security · Jun 14, 2026
- Max-Severity Ivanti Flaw Exploited 24 Hours After DisclosureDark Reading · Jun 11, 2026
- Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC ReleaseCyber Security News · Jun 11, 2026
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesThe Hacker News · Jun 10, 2026
- Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)Help Net Security · Jun 10, 2026
- Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9The Register Security · Jun 10, 2026
- CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti SentryRapid7 Blog · Jun 10, 2026
- Critical Vulnerabilities Patched in Fortinet, Ivanti ProductsSecurityWeek · Jun 10, 2026
- Ivanti: Max severity Sentry flaw allows code execution as rootBleepingComputer · Jun 10, 2026
- More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)watchTowr Labs · Jun 10, 2026