VORANT. Threat Intelligence Sign in Get the full feed

Critical Ivanti Sentry, Oracle PeopleSoft flaws exploited

critical vulnerability technologyinfrastructure

Three actively exploited zero-days disclosed in Ivanti Sentry (CVE-2026-10520), Oracle PeopleSoft (CVE-2026-35273), and Check Point Security Gateways (CVE-2026-50751) during the week of 8-14 June 2026.

France's CERT-FR published its weekly bulletin covering significant vulnerabilities from 8-14 June 2026, highlighting three actively exploited critical flaws. Ivanti Sentry CVE-2026-10520 (CVSS 10.0) allows remote code execution and is under active exploitation; a second Ivanti Sentry flaw, CVE-2026-10523 (CVSS 9.9), has public exploit code available. Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) is also being exploited in the wild for remote code execution. Check Point Security Gateways and Spark Firewalls CVE-2026-50751 (CVSS 9.3) is exploited to bypass security policies.

The bulletin also notes an actively exploited Google Chrome vulnerability (CVE-2026-11645, CVSS 8.8) and a long list of critical-severity patches from Microsoft, SAP, Fortinet, IBM, Apache, Adobe, Splunk, and other vendors. Most of these have no evidence of active exploitation at publication time. CERT-FR updated its advisory on the Microsoft Exchange Server vulnerability CVE-2026-42897, noting that Microsoft released patches on 9 June 2026. The bulletin reminds organisations to prioritise patching based on a full risk analysis, not solely on the criticality scores published in advisories.

Mentioned in this report

Vulnerabilities CVE-2024-3400KEVCVE-2025-68121CVE-2026-10520KEVCVE-2026-10523CVE-2026-10879CVE-2026-11645KEVCVE-2026-12027CVE-2026-20253KEVCVE-2026-25089KEVCVE-2026-26142CVE-2026-27671CVE-2026-29167CVE-2026-34910KEVCVE-2026-35273KEVCVE-2026-42271KEVCVE-2026-42897KEVCVE-2026-44631CVE-2026-44748CVE-2026-44815CVE-2026-45657CVE-2026-47291CVE-2026-47643CVE-2026-49413CVE-2026-50751KEVCVE-2026-7473KEVCVE-2026-8633

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-026

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free