DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-10520PUBLISHED: 2026-06-09
CRITICALCVE-2026-10520★ CISA KEV LISTED

Ivanti Sentry Pre-Auth OS Command Injection RCE

VENDOR: Ivanti//PRODUCT: Ivanti Sentry (formerly MobileIron Sentry)
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A pre-authentication OS command injection vulnerability (CWE-78) in Ivanti Sentry's MICS configuration API endpoint (/mics/api/v2/sentry/mics-config/handleMessage) that passes user-supplied input directly into OS command execution, enabling unauthenticated remote root-level RCE with no user interaction required. WatchTowr Labs published a full technical analysis and public PoC on June 10, 2026. Shadowserver confirmed active exploitation within 48 hours of PoC release, reporting mass exploitation attempts and at least 2 backdoored instances out of 19 vulnerable internet-exposed appliances scanned; CISA added to KEV on June 11 with a 3-day federal remediation deadline.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSIvanti Sentry versions 10.5.1, 10.6.1, 10.7.0 and earlier (all R10.5.x, R10.6.x, R10.7.x trains)
  • https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523
  • https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/
  • https://www.rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry/
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://www.helpnetsecurity.com/2026/06/10/ivanti-sentry-cve-2026-10520-cve-2026-10523/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn