Ivanti Sentry patch release for CVE-2026-10520 and CVE-2026-10523
Security Patch Release
Summary
Hide ▲
Show ▼
Ivanti released a patch bundle for Sentry after identifying two critical vulnerabilities in the secure mobile gateway appliance, including CVE-2026-10520 and CVE-2026-10523. The update addresses an OS command injection flaw that can lead to code execution as root and an authentication bypass that can let unauthenticated attackers create rogue admin accounts. Ivanti said it had no evidence of exploitation in the wild and urged administrators to upgrade to R10.5.2, R10.6.2, or R10.7.1.
Related Happenings
NHS England Digital libssh2 update advisory for CVE-2026-55200
Advisory/Mitigation
H score38
First: 29.06.2026 10:06
Last: 29.06.2026 10:06
Sources 1
About this happening:
NHS England Digital has issued an update advisory for libssh2 after a public proof-of-concept surfaced for CVE-2026-55200. The flaw can let a malicious or compro...
NHS England Digital libssh2 update advisory for CVE-2026-55200
Advisory/MitigationAbout this happening: NHS England Digital has issued an update advisory for libssh2 after a public proof-of-concept surfaced for CVE-2026-55200. The flaw can let a malicious or compro...
Kandji security patch release for CVE-2026-39118
Security Patch Release
H score17
First: 25.06.2026 14:00
Last: 25.06.2026 14:00
Sources 1
About this happening:
Kandji fixed its MDM agent on macOS and assigned CVE-2026-39118 after validation showed a trust issue that could let a standard user disable enterprise security contro...
Kandji security patch release for CVE-2026-39118
Security Patch ReleaseAbout this happening: Kandji fixed its MDM agent on macOS and assigned CVE-2026-39118 after validation showed a trust issue that could let a standard user disable enterprise security contro...
Redis security patch release for CVE-2026-23479
Security Patch Release
H score24
First: 03.06.2026 16:47
Last: 03.06.2026 16:47
Sources 1
About this happening:
Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...
Redis security patch release for CVE-2026-23479
Security Patch ReleaseAbout this happening: Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch Release
H score42
First: 27.05.2026 13:06
Last: 27.05.2026 13:06
Sources 1
About this happening:
LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch ReleaseAbout this happening: LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...
Latest development: 16.06.2026 13:47
CISA added CVE-2026-48172/CVE-2026-54420 in the LiteSpeed cPanel user-end plugin to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to secure affected servers within three days under BOD 26-04. The affected plugin versions before 2.4.8 are described as actively exploited, with FTP or web shell access enabling root escalation on shared hosting servers running CloudLinux/CageFS.
Drupal core security update for CVE-2026-9082
Security Patch Release
H score74
First: 22.05.2026 16:14
Last: 22.05.2026 16:14
Sources 1
About this happening:
Drupal released security updates for CVE-2026-9082, a highly critical SQL injection flaw affecting PostgreSQL-backed sites, and urged administrators to upgrade immed...
Drupal core security update for CVE-2026-9082
Security Patch ReleaseAbout this happening: Drupal released security updates for CVE-2026-9082, a highly critical SQL injection flaw affecting PostgreSQL-backed sites, and urged administrators to upgrade immed...
Timeline
-
10.06.2026 09:26 4 articles · 1mo ago
Ivanti patches CVE-2026-10520 and CVE-2026-10523 in Sentry
Mitigation Patch UpdateIvanti released Sentry versions R10.5.2, R10.6.2, and R10.7.1 to fix two critical flaws in the Sentry secure mobile gateway appliance, including CVE-2026-10520, an OS command injection issue that can enable remote code execution as root, and CVE-2026-10523, a remote authentication bypass that can let unauthenticated attackers create rogue administrative accounts and gain full administrative access. Ivanti said it had no evidence of exploitation in the wild at disclosure and advised administrators to upgrade.
Show sources
- Ivanti: Max severity Sentry flaw allows code execution as root — www.bleepingcomputer.com — 10.06.2026 09:26
- Ivanti: Max severity Sentry flaw allows code execution as root — www.bleepingcomputer.com — 10.06.2026 09:26
- Max severity Ivanti Sentry vulnerability now exploited in attacks — www.bleepingcomputer.com — 11.06.2026 09:20
- Ivanti Sentry Exploitation Attempts Hitting Honeypots — www.securityweek.com — 12.06.2026 12:44