U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14

2026-06-12T20:51:44Z54728508147e3d01cdd056b7d618abfa12b924d14dcbe54a51ac19a3d8bd90d7
Arista EOSBitLockerCISACVE-2025-8088CVE-2026-10520CVE-2026-25089Chromium V8Cisco Catalyst SD-WANFortiSandboxFortinetGreatXMLIoT camerasIvanti SentryJDY botnetKnown Exploited VulnerabilitiesOnyxC2Oracle PeopleSoftShinyHuntersWinRARmalware-as-a-servicethreat-intelligencewebcamXPzero-day

What happened

Security Affairs roundup: CISA added Ivanti Sentry OS command‑injection RCE (CVE-2026-10520, CVSS 10.0) to its Known Exploited Vulnerabilities catalog and urged urgent patching as active exploitation was observed. Multiple other high‑risk incidents were reported: a critical Oracle PeopleSoft zero‑day exploited by ShinyHunters to breach 100+ organizations; Fortinet patched a critical FortiSandbox command‑injection RCE (CVE-2026-25089, CVSS 9.8); and researcher Chaotic Eclipse published a BitLocker bypass (GreatXML) zero‑day with no patch. Additional coverage includes OnyxC2 malware‑as‑a‑service

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
54728508147e3d01cdd056b7d618abfa12b924d14dcbe54a51ac19a3d8bd90d7
Enrichment time
2026-06-12T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.