[CVE, 긴급패치][KISA 보안취약점 정보포털 진흥원] 美 CISA 발표 주요 Exploit 정보공유(Update. 2026-06-11)

2026-06-12
조회수 219

확인 시간 : 2026-06-12 06:15

KISA 보안취약점 정보포털 진흥원 : 취약점 정보 > 보안공지


[게시판] https://knvd.krcert.or.kr/info/vuln/notice

[게시글] https://knvd.krcert.or.kr/info/vuln/notice/detail?id=6a297bf032efaab037305fbf


제목 : 美 CISA 발표 주요 Exploit 정보공유(Update. 2026-06-11)

□ 개요
o 美 CISA에서 현재 자주 악용되고 있는 취약점 목록 발표 [1]
o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고

□ 영향을 받는 제품


                       CVE                                         제조사                                취약점                                            내용                                           조치사항

CVE-2026-10520IvantiIvanti Sentry OS Command Injection VulnerabilityIvanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.


※ 하단의 참고 사이트를 확인하여 업데이트 수행 [1]

□ 참고사이트
[1] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

□ 작성 : 위협대응단 AI취약점대응팀


카카오톡 채널 채팅하기 버튼