Max severity Ivanti Sentry vulnerability now exploited in attacks

2026-06-11T07:23:31Z25c81845cfb29e66bd2ce3206bd7741f88d42a1cce3037e028af1b35a942f2df
CVE-2026-5027ExchangeGitHubGreenPlasmaIvantiJDY botnetLangflowMiasmaMicrosoftMicrosoft DefenderMiniPlasmaOracle PeopleSoftRoguePlanetSentryShinyHuntersXSSYellowKeycredential stealerdata theftexposed servicesnpm securitypath traversalremote code executionrootsupply chain

What happened

Multiple active, high-impact incidents affecting enterprise infrastructure and supply chains were reported. A maximum-severity Ivanti Sentry flaw enabling remote code execution as root is being actively exploited on Internet-exposed secure mobile gateways. Langflow suffers a high-severity path traversal (CVE-2026-5027) used to write arbitrary files on exposed servers. Microsoft disclosed and patched multiple actively exploited issues (Exchange XSS zero-day, privilege‑escalation flaws referenced as YellowKey/GreenPlasma/MiniPlasma, and a newly public Defender exploit “RoguePlanet”). Other noted

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
25c81845cfb29e66bd2ce3206bd7741f88d42a1cce3037e028af1b35a942f2df
Enrichment time
2026-06-11T07:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.