Critical Ivanti Sentry, Oracle PeopleSoft flaws exploited
Three actively exploited zero-days disclosed in Ivanti Sentry (CVE-2026-10520), Oracle PeopleSoft (CVE-2026-35273), and Check Point Security Gateways (CVE-2026-50751) during the week of 8-14 June 2026.
France's CERT-FR published its weekly bulletin covering significant vulnerabilities from 8-14 June 2026, highlighting three actively exploited critical flaws. Ivanti Sentry CVE-2026-10520 (CVSS 10.0) allows remote code execution and is under active exploitation; a second Ivanti Sentry flaw, CVE-2026-10523 (CVSS 9.9), has public exploit code available. Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) is also being exploited in the wild for remote code execution. Check Point Security Gateways and Spark Firewalls CVE-2026-50751 (CVSS 9.3) is exploited to bypass security policies.
The bulletin also notes an actively exploited Google Chrome vulnerability (CVE-2026-11645, CVSS 8.8) and a long list of critical-severity patches from Microsoft, SAP, Fortinet, IBM, Apache, Adobe, Splunk, and other vendors. Most of these have no evidence of active exploitation at publication time. CERT-FR updated its advisory on the Microsoft Exchange Server vulnerability CVE-2026-42897, noting that Microsoft released patches on 9 June 2026. The bulletin reminds organisations to prioritise patching based on a full risk analysis, not solely on the criticality scores published in advisories.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-026
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free