cisa-kev

Tag

Cards List
#cisa-kev

CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

Hacker News Top · 2026-07-16 Cached

Fortinet FortiSandbox contains a critical unauthenticated OS command injection vulnerability (CVE-2026-25089) actively exploited in the wild, added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026.

0 favorites 0 likes
#cisa-kev

Ivanti Sentry pre-auth RCE (CVE-2026-10520) – CVSS 10.0, public PoC, CISA KEV

Hacker News Top · 2026-06-11 Cached

A maximum-severity unauthenticated OS command injection vulnerability (CVE-2026-10520, CVSS 10.0) in Ivanti Sentry is actively exploited, with public PoC released and CISA KEV listing demanding a 3-day remediation. The article details how to identify exposed Ivanti Sentry instances on networks.

0 favorites 0 likes
← Back to home

Submit Feedback