CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release

2026-06-12T08:51:42Z9bc29a8aa330d1f1ed18849cdf49469ef5fe1934423e2f2511b04c4d9b914979

What happened

Multiple high-impact incidents and disclosures: active exploitation of a critical OS command injection in Ivanti Sentry (CVE-2026-10520) allowing RCE as root shortly after patches; Fortinet patched a critical FortiSandbox command-injection RCE (CVE-2026-25089, CVSS 9.8); continued abuse of a patched WinRAR path-traversal (CVE-2025-8088) by threat actors. Additional high-risk developments include Chaotic Eclipse’s public exploits (GreatXML BitLocker bypass and RoguePlanet Defender race condition) with no available vendor patches, the emergence of OnyxC2 as a commercial stealer (MaaS) targeting

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9bc29a8aa330d1f1ed18849cdf49469ef5fe1934423e2f2511b04c4d9b914979
Enrichment time
2026-06-12T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release · Baitaphish