U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
2026-06-12T20:51:44Z•54728508147e3d01cdd056b7d618abfa12b924d14dcbe54a51ac19a3d8bd90d7
Arista EOSBitLockerCISACVE-2025-8088CVE-2026-10520CVE-2026-25089Chromium V8Cisco Catalyst SD-WANFortiSandboxFortinetGreatXMLIoT camerasIvanti SentryJDY botnetKnown Exploited VulnerabilitiesOnyxC2Oracle PeopleSoftShinyHuntersWinRARmalware-as-a-servicethreat-intelligencewebcamXPzero-day
What happened
Security Affairs roundup: CISA added Ivanti Sentry OS command‑injection RCE (CVE-2026-10520, CVSS 10.0) to its Known Exploited Vulnerabilities catalog and urged urgent patching as active exploitation was observed. Multiple other high‑risk incidents were reported: a critical Oracle PeopleSoft zero‑day exploited by ShinyHunters to breach 100+ organizations; Fortinet patched a critical FortiSandbox command‑injection RCE (CVE-2026-25089, CVSS 9.8); and researcher Chaotic Eclipse published a BitLocker bypass (GreatXML) zero‑day with no patch. Additional coverage includes OnyxC2 malware‑as‑a‑service
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 54728508147e3d01cdd056b7d618abfa12b924d14dcbe54a51ac19a3d8bd90d7
- Enrichment time
- 2026-06-12T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.