# CERT-FR flags exploited Ivanti, Oracle, CheckPoint flaws

Published: 2026-06-15 · Severity: high · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/5ddd67d4-fab9-5856-85b5-69261afb3e4e/cert-fr-flags-exploited-ivanti-oracle-checkpoint-flaws

> France's CERT-FR highlights actively exploited critical vulnerabilities in Ivanti Sentry, Oracle PeopleSoft, CheckPoint firewalls, and Google Chrome from the week of 8–14 June 2026.

The French national CERT (CERT-FR) published its weekly threat bulletin covering significant vulnerabilities disclosed between 8 and 14 June 2026. The advisory highlights four actively exploited critical flaws: CVE-2026-10520 (CVSS 10.0) in Ivanti Sentry enabling remote code execution, CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft also allowing RCE, CVE-2026-50751 (CVSS 9.3) in CheckPoint Security Gateways and Spark Firewalls permitting security-policy bypass, and CVE-2026-11645 (CVSS 8.8) in Google Chrome leading to RCE. Public exploit code exists for a second Ivanti Sentry vulnerability (CVE-2026-10523, CVSS 9.9) and for flaws in Splunk Enterprise/Cloud Platform (CVE-2026-20253) and FreeBSD (CVE-2026-49413).

The bulletin also catalogues dozens of additional high-severity CVEs across Microsoft Windows/Edge/Azure, SAP NetWeaver, Adobe ColdFusion, Apache HTTP Server, IBM WebSphere, Fortinet FortiSandbox, and other enterprise platforms, though these lack public evidence of exploitation. CERT-FR further references older but still-exploited vulnerabilities in Palo Alto PAN-OS (CVE-2024-3400), Ubiquiti UniFi OS (CVE-2026-34910), and LiteLLM (CVE-2026-42271), reinforcing the persistent threat from unpatched systems. The advisory underscores the urgency of applying vendor patches for all listed issues, particularly the four confirmed in-the-wild exploits.

## Mentioned in this report

- Vulnerabilities: CVE-2024-3400 (KEV), CVE-2025-68121, CVE-2026-10520 (KEV), CVE-2026-10523, CVE-2026-10879, CVE-2026-11645 (KEV), CVE-2026-12027, CVE-2026-20253 (KEV), CVE-2026-25089 (KEV), CVE-2026-26142, CVE-2026-27671, CVE-2026-29167, CVE-2026-34910 (KEV), CVE-2026-35273 (KEV), CVE-2026-42271 (KEV), CVE-2026-42897 (KEV), CVE-2026-44631, CVE-2026-44748, CVE-2026-44815, CVE-2026-44963, CVE-2026-45657, CVE-2026-47291, CVE-2026-47643, CVE-2026-47928, CVE-2026-49413, CVE-2026-50751 (KEV), CVE-2026-7473 (KEV), CVE-2026-8633

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-026/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5ddd67d4-fab9-5856-85b5-69261afb3e4e/cert-fr-flags-exploited-ivanti-oracle-checkpoint-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
