CVE Tools
Back to feed
PoC public Ivanti Sentry rce Ivanti auth-bypass

Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

Ivanti has published urgent fixes for its gateway appliances after researchers and watchTowr Labs disclosed a publicly available proof of concept for an Ivanti Sentry remote code execution issue. The affected component is associated with CVE-2026-10520 (CVSS 10), and a related authentication/privilege bypass is tracked as CVE-2026-10523 (CVSS 9.9), which can enable creation of administrative accounts and full administrative access. Because these systems sit at the edge of corporate traffic, unpatched deployments face a heightened risk of full administrative compromise; organizations should review logs and upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.