More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
Today, Ivanti published an advisory. “No way?” we hear you say. "Yes way!" Today’s advisory outlines two vulnerabilities in Ivanti’s Sentry product, appealing directly to our inner desire for sophisticated server-side, pre-authenticated vulnerabilities. CVE-2026-10520 An OS Command Injection
Sources
- T1More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)watchTowr Labs
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| kev short fuse — 3 days to remediate | 15 |
| public poc — 7 repositories | 20 |
| widely deployed | 15 |