discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Ivanti: Max severity Sentry flaw allows code execution as root

Ivanti patched two critical Sentry flaws, including a max-severity bug that can let remote attackers run code as root.

By Sergiu Gatlan·Jun 10·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Ivanti: Max severity Sentry flaw allows code execution as root
Image: bleepingcomputer.com

Ivanti fixed an OS command injection flaw and an auth bypass in Sentry, its secure mobile gateway appliance. The company says it has no evidence of exploitation so far and urges customers to upgrade.

Why it matters

Ivanti devices have repeatedly been targeted because they can open a path into enterprise networks. A root-level remote code execution bug in a gateway appliance is especially dangerous for organizations that expose the product to the internet or rely on it for mobile access.

Ivanti found two big holes in a security gate for company phones and networks. One hole could let a stranger take over the gate like a master key, and the other could let them run dangerous commands like they were the boss.

Analysis

Ivanti says it has patched two critical vulnerabilities in Sentry, its secure mobile gateway appliance formerly known as MobileIron Sentry. The highest-severity issue, tracked as CVE-2026-10520, is an OS command injection flaw that can let a remote attacker execute code with root privileges.

The second bug, CVE-2026-10523, is an authentication bypass. According to the article, an unauthenticated attacker could exploit it remotely to create rogue administrative accounts and gain full administrative access.

Ivanti released fixes in Sentry versions R10.5.2, R10.6.2, and R10.7.1. The company said it is not aware of customers being exploited by these vulnerabilities at the time of disclosure and said there is no known public exploitation that would provide indicators of compromise.

The story also places the bugs in context: Ivanti vulnerabilities have often been used in real-world attacks because they can give cybercriminals an easy entry point into enterprise networks and the sensitive data those networks hold. The article points to recent zero-day activity against Ivanti products, including an Endpoint Manager Mobile flaw that CISA told U.S. federal agencies to patch in May.

For defenders, the practical takeaway is straightforward: treat Sentry as urgent patching territory, especially if the appliance is reachable from untrusted networks. The combination of root-level code execution and remote administrative takeover makes both flaws high-risk even before any public exploitation appears.

Key points

  • Ivanti patched two critical Sentry vulnerabilities, including a maximum-severity OS command injection flaw.
  • CVE-2026-10520 can let a remote attacker execute code with root privileges.
  • CVE-2026-10523 is an authentication bypass that could let an attacker create rogue admin accounts.
  • Ivanti says it has no evidence of customer exploitation at the time of disclosure.
  • The company released fixes in Sentry versions R10.5.2, R10.6.2, and R10.7.1.
The Upside

If organizations patch quickly, they can close off both the root-level code execution path and the admin takeover bug before attackers get a broad foothold. Ivanti also says it has no evidence of active exploitation so far, which gives defenders a window to respond.

The Downside

If patching is delayed, attackers could use either flaw to break into exposed Sentry systems and move into corporate networks. The article notes that Ivanti vulnerabilities have repeatedly been used in attacks, so even newly disclosed bugs can become attractive targets fast.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytech

Author

Sergiu Gatlan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 10, 2026

Source

bleepingcomputer.com

Share

Topics

securitytech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…