📦

standalone_sentry

Vendor: ivanti

Actively Exploited 1 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 2 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 39.83% Exploit Prob.
Latest CVE CVE-2026-10523 Jun 09

Security Vulnerability Index

Page 1 / 1
9.9 CVSS
CVE-2026-10523
Exploit Found

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

EPSS: 47.19%
Critical Target
10.0 CVSS
CVE-2026-10520
RCE Exploit Found

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

EPSS: 99.04%
8.8 CVSS

Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.

EPSS: 0.25%
8.8 CVSS

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

EPSS: 12.84%