An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
https://www.securityweek.com/critical-vulnerabilities-patched-in-fortinet-ivanti-products/
https://www.helpnetsecurity.com/2026/06/10/ivanti-sentry-cve-2026-10520-cve-2026-10523/
https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html
https://github.com/imbas007/RCE-CVE-2026-10520-CVE-2026-10523
https://github.com/gagaltotal/CVE-2026-10523-Ivanti-sentry
https://github.com/0xBlackash/CVE-2026-10520
https://github.com/HORKimhab/CVE-2026-10520-10523
https://github.com/ogenich/CVE-2026-10520
https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523