CVE-2026-10523
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
- Published Jun 9, 2026
- CVSS 9.8 critical
- 53.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available