CVE-2026-10523: Ivanti Standalone Sentry

Critical severity, CVSS 9.8. EPSS: 53.1% chance of exploitation in the next 30 days.

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Affected products

  • Ivanti Standalone Sentry: before 10.5.2 (fixed in 10.5.2); from 10.6.0, before 10.6.2 (fixed in 10.6.2); version 10.7.0 only

Published 2026-06-09. Last modified 2026-07-23.