This week’s release introduces new managed protection to address a critical pre-authentication OS command injection vulnerability in Ivanti Sentry (CVE-2026-10520).
Key Findings
- CVE-2026-10520: An OS command injection vulnerability in Ivanti Sentry allows remote, unauthenticated attackers to execute arbitrary system commands with root privileges. The flaw stems from improper sanitization of input strings parsed during internal configuration handling.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 500a90789f874345b60b0de7242fdf83 | N/A | Ivanti Sentry – Command Injection – CVE:CVE-2026-10520 | Log | Block | This is a new detection. |
Source: Cloudflare
Latest Posts
- MC1465569: Power Platform Adds Column-Based Filtering for Secure Dataverse Record Access

- Amazon CloudWatch now supports warm-up periods for alarms

- MC1465569: Power Platform Adds Column-Based Filtering for Secure Dataverse Record Access

- MC1465563: Dynamics 365 Project Operations Adds Accrued Revenue Reconciliation Capability







