CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
2026-06-12T02:52:10Z•92714d9c7dd4eba0c929207772bd72bcc5df2ba730c2eb6fd7cb5280f895dfa9
AI wormsBitLockerCISA KEVCVE-2025-8088CVE-2026-10520CVE-2026-25089FortinetGreatXMLIvanti SentryJDY botnetMaaSMicrosoft DefenderOnyxC2RoguePlanetTchap breachWinRARbotnetexploitationzero-day
What happened
A cluster of high-impact security events: attackers are actively exploiting a critical Ivanti Sentry OS command injection (CVE-2026-10520) to achieve root RCE on internet-exposed gateways shortly after patches were published. Fortinet released fixes for a critical FortiSandbox command injection (CVE-2026-25089, CVSS 9.8). Researcher Chaotic Eclipse published multiple powerful zero-days/PoCs — GreatXML (BitLocker bypass yielding SYSTEM in Recovery Mode, unpatched) and RoguePlanet (Microsoft Defender race-condition PoC granting SYSTEM). Meanwhile, OnyxC2 surfaced as a commercial stealer MaaS (bq
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 92714d9c7dd4eba0c929207772bd72bcc5df2ba730c2eb6fd7cb5280f895dfa9
- Enrichment time
- 2026-06-12T02:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.