An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html
https://www.securityweek.com/critical-vulnerabilities-patched-in-fortinet-ivanti-products/
https://www.helpnetsecurity.com/2026/06/10/ivanti-sentry-cve-2026-10520-cve-2026-10523/
https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html
https://github.com/imbas007/RCE-CVE-2026-10520-CVE-2026-10523
https://github.com/gduma-phData/patch-CVE-2026-10520
https://github.com/emilliewatson96/spryCVE-2026-10520
https://github.com/VixianSchool/nuclei-cve-check
https://github.com/gagaltotal/CVE-2026-10523-Ivanti-sentry
https://github.com/HORKimhab/poc-cve-collection
https://github.com/rozetyp/vuln-intel-mcp
https://github.com/0xBlackash/CVE-2026-10520
https://github.com/HORKimhab/CVE-2026-10520-10523
https://github.com/Layer-6/CVE-2026-5027-Langflow
https://github.com/ogenich/CVE-2026-10520
https://github.com/intelseclab/poc-archive
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520
Published: 2026-06-09
Updated: 2026-07-23
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99915
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest