CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
Ivanti Sentry (formerly MobileIron Sentry) contains two critical vulnerabilities: CVE-2026-10520 (CVSS 10.0), an unauthenticated OS command injection in the /mics/api/v2/sentry/mics-config/handleMessage endpoint allowing root RCE, and CVE-2026-10523 (CVSS 9.9), an authentication bypass enabling arbitrary admin account creation. A public PoC for CVE-2026-10520 was published by watchTowr on June 10, 2026, making in-the-wild exploitation imminent.