A critical, unpatched CVSS 10.0 command injection flaw in VeloCloud Orchestrator is being actively exploited, requiring immediate upgrade to fixed versions and comprehensive incident response measures.
Four ManageEngine products contain a critical vulnerability that allows unauthenticated attackers to perform account takeovers via manipulated SSO mechanisms.
The OS command injection vulnerability CVE-2026-10520 in Ivanti Sentry is actively exploited by attackers; CISA orders patching within 72 hours for federal agencies.