More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
AdvisoryIvanti SentryMobileIron Sentry Read at watchTowr Labs
Below is the opening; the full story is at watchTowr Labs.
From watchTowr Labs
CVE-2026-10520-CVE-2026-10523?language=en_US&ref=labs.watchtowr.com">Today, Ivanti published an advisory.
“No way?” we hear you say. "Yes way!" a random dog screams back at you, across the street.
Today’s rare advisory outlines two vulnerabilities in Ivanti’s Sentry product, appealing directly to our inner desire for sophisticated server-side, pre-authenticated vulnerabilities.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.