CiberLATAMbywhalemate

GlobalProtect and Ivanti Lead Active Exploitation

CVE-2019-1579 in GlobalProtect and CVE-2026-10520 in Ivanti Sentry are among July 2026's most actively exploited flaws.

Whalemate Labs · AI-assisted researchJul 15, 20262 min read

CVE-2019-1579 in GlobalProtect is being actively exploited on unpatched or unisolated instances, while o3.security places Ivanti Sentry CVE-2026-10520 among the most actively exploited vulnerabilities, with a 99% EPSS score and CISA KEV presence.

GlobalProtect remains under active exploitation

Devel Group said CVE-2019-1579 in GlobalProtect, described as a legacy issue, is being actively exploited on instances that have not been updated or isolated. The same report says it affects older GlobalProtect portals and recommends urgently auditing versions, updating, or isolating any vulnerable instance because of the risk identified.

The firm also detailed additional high-severity vulnerabilities in PAN-OS and components of Prisma Access and GlobalProtect. Those included CVE-2026-0283, described as an authentication bypass, CVE-2026-0286, authenticated command injection, CVE-2026-0288, a buffer overflow, and CVE-2026-0285, a possible SSRF. In that context, it recommended threat hunting and specific alerting in the SOC to detect exploitation attempts.

Ivanti Sentry ranks among the most exploited

The o3.security database placed CVE-2026-10520, identified as Ivanti Sentry OS Command Injection, among the vulnerabilities with the most active exploitation right now. The catalog also marks it as confirmed in CISA Known Exploited Vulnerabilities and gives it a 99% EPSS exploitation probability.

In the same set of findings, o3.security pointed to CVE-2024-27199, JetBrains TeamCity Relative Path Traversal, and CVE-2025-32432, Craft CMS Code Injection, as other flaws under active exploitation. Both are listed with a 100% EPSS score and presence in CISA KEV, although the source excerpt did not provide specific cases.

A technical snapshot centered on access and credential theft

Iurlek's technical blog published a roundup of 27 critical vulnerabilities on July 9, 2026. In that post, it said there is confirmed public exploitation of a flaw that allows attackers, by manipulating the admin-request endpoint, to steal vault keys and take over affected accounts. The excerpt reviewed here does not provide the CVE identifier or the specific product.

The overlap across these sources points to a set of vulnerabilities being actively exploited in perimeter infrastructure and enterprise platforms used in corporate environments. That includes VPN gateways, GlobalProtect portals, Ivanti Sentry, TeamCity, and Craft CMS, all components that can be exposed in enterprise networks, banks, and systems that depend on remote access.

Exposure outlook

The available material does not include a regional measurement for Latin America or confirmed local cases, but it does show a clear risk pattern in technology used as an entry point into corporate networks. In practice, the priority signaled by CISA KEV, EPSS, and reports of active exploitation falls on teams that manage perimeter services, remote access, and platforms with sensitive credentials.

Sources

View all