CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
2026-06-12T08:51:42Z•9bc29a8aa330d1f1ed18849cdf49469ef5fe1934423e2f2511b04c4d9b914979
What happened
Multiple high-impact incidents and disclosures: active exploitation of a critical OS command injection in Ivanti Sentry (CVE-2026-10520) allowing RCE as root shortly after patches; Fortinet patched a critical FortiSandbox command-injection RCE (CVE-2026-25089, CVSS 9.8); continued abuse of a patched WinRAR path-traversal (CVE-2025-8088) by threat actors. Additional high-risk developments include Chaotic Eclipse’s public exploits (GreatXML BitLocker bypass and RoguePlanet Defender race condition) with no available vendor patches, the emergence of OnyxC2 as a commercial stealer (MaaS) targeting
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9bc29a8aa330d1f1ed18849cdf49469ef5fe1934423e2f2511b04c4d9b914979
- Enrichment time
- 2026-06-12T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.