Ivanti: Max severity Sentry flaw allows code execution as root
2026-06-10T07:23:29Z•618d16f5b5f712e014c80b148354278b04709326decca6f2a5885dbdbcae374c
backup-rcecheck-pointchromecisadata-exposuregithubgoogleivantimalwaremicrosoftmicrosoft-defenderopenclaw','ai_phishingpassword-stealerpatch-tuesdayqilinremote_code_executionrogueplanetrootsapsentryservicenowveeamvpnvulnerabilityzero-day
What happened
Multiple high-impact security stories: Ivanti patched two critical flaws in its Sentry secure mobile gateway, including a maximum-severity remote code‑execution vulnerability that can be abused to run code as root. Multiple zero-days and exploited bugs were disclosed or patched — including a Microsoft Defender zero-day (dubbed “RoguePlanet”) that grants SYSTEM privileges, an actively exploited Check Point Remote Access/Mobile Access VPN flaw (CISA ordered rapid remediation), and an emergency Chrome zero-day patch. Microsoft’s June 2026 Patch Tuesday fixed ~200 flaws (including three publicly‑d
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 618d16f5b5f712e014c80b148354278b04709326decca6f2a5885dbdbcae374c
- Enrichment time
- 2026-06-10T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.