Database/Control plane, storage & DevOps

Ivanti Sentry: OS command injection
CVSS 10.0CVE-2026-10520Control plane, storage & DevOpsKnown exploitedcurated
Impact
OS command injection -> unauthenticated root-level remote code execution
Who can reach it
Network (remote)
What to do
Control-plane: patch to R10.5.2/R10.6.2/R10.7.1; rebuild the appliance if it was exposed
References
Related entries
- Cisco Secure Firewall Management Center: unauthenticated HTTP request yields root on the applianceCVE-2026-20079 · Cisco Secure Firewall Management Center (web interface)Critical
- Kestra: suffix-match auth bypass on /configs gives unauthenticated workflow execution as rootCVE-2026-49869 · Kestra AuthenticationFilter (suffix match on the /configs path whitelist)Critical
- Linux crypto driver for Marvell OCTEON TX: The scatter-gather cleanup path in the Marvell OCTEON TX crypto driver usesCVE-2026-74280 · Linux crypto driver for Marvell OCTEON TXCritical
- Linux VXLAN driver (neighbour hardware address read in route_shortcircuit): `route_shortcircuit()` reads a neighbour'sCVE-2026-74475 · Linux VXLAN driver (neighbour hardware address read in route_shortcircuit)Critical
- Cisco ISE: unauthenticated API endpoint allows full authentication bypass on the applianceCVE-2026-76460 · Cisco Identity Services Engine (unauthenticated API endpoint)Critical
- SonicWall SMA1000: pre-auth SSRF via an unintended alternate access path in the Work Place interfaceCVE-2026-83548 · SonicWall SMA1000 appliance (Work Place interface, alternate access path)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.