Ivanti urges Sentry users to patch two critical bugs

https://image.theregister.com/5244794.jpg?imageId=5244794&x=0&y=28.33&cropw=100&croph=71.67&panox=0&panoy=28.33&panow=100&panoh=71.67&width=1200&height=683

Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9

Remote, unauthenticated RCE with root privileges is about as bad as it gets

It's patch time for Ivanti customers again after the security shop disclosed another two critical vulnerabilities in one of its products.

Both bugs affect Ivanti Sentry, a mobile gateway that forms part of its broader unified endpoint management platform.

The first and worst of the two is CVE-2026-10520 (10.0), a max-severity vulnerability that allows a remote, unauthenticated attacker to execute code with root privileges.

Flaws that allow root-level code execution without authentication are about as bad as vulnerabilities get, which explains the perfect-10 rating.

The only saving grace is that, by the vendor's reckoning, no one has successfully exploited it in the wild… yet. Public disclosures tend to start a figurative countdown timer when it comes to attackers exploiting bugs, and although Ivanti...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more