GlobalProtect and Ivanti Lead Active Exploitation
CVE-2019-1579 in GlobalProtect and CVE-2026-10520 in Ivanti Sentry are among July 2026's most actively exploited flaws.
CVE-2019-1579 in GlobalProtect is being actively exploited on unpatched or unisolated instances, while o3.security places Ivanti Sentry CVE-2026-10520 among the most actively exploited vulnerabilities, with a 99% EPSS score and CISA KEV presence.
GlobalProtect remains under active exploitation
Devel Group said CVE-2019-1579 in GlobalProtect, described as a legacy issue, is being actively exploited on instances that have not been updated or isolated. The same report says it affects older GlobalProtect portals and recommends urgently auditing versions, updating, or isolating any vulnerable instance because of the risk identified.
The firm also detailed additional high-severity vulnerabilities in PAN-OS and components of Prisma Access and GlobalProtect. Those included CVE-2026-0283, described as an authentication bypass, CVE-2026-0286, authenticated command injection, CVE-2026-0288, a buffer overflow, and CVE-2026-0285, a possible SSRF. In that context, it recommended threat hunting and specific alerting in the SOC to detect exploitation attempts.
Ivanti Sentry ranks among the most exploited
The o3.security database placed CVE-2026-10520, identified as Ivanti Sentry OS Command Injection, among the vulnerabilities with the most active exploitation right now. The catalog also marks it as confirmed in CISA Known Exploited Vulnerabilities and gives it a 99% EPSS exploitation probability.
In the same set of findings, o3.security pointed to CVE-2024-27199, JetBrains TeamCity Relative Path Traversal, and CVE-2025-32432, Craft CMS Code Injection, as other flaws under active exploitation. Both are listed with a 100% EPSS score and presence in CISA KEV, although the source excerpt did not provide specific cases.
A technical snapshot centered on access and credential theft
Iurlek's technical blog published a roundup of 27 critical vulnerabilities on July 9, 2026. In that post, it said there is confirmed public exploitation of a flaw that allows attackers, by manipulating the admin-request endpoint, to steal vault keys and take over affected accounts. The excerpt reviewed here does not provide the CVE identifier or the specific product.
The overlap across these sources points to a set of vulnerabilities being actively exploited in perimeter infrastructure and enterprise platforms used in corporate environments. That includes VPN gateways, GlobalProtect portals, Ivanti Sentry, TeamCity, and Craft CMS, all components that can be exposed in enterprise networks, banks, and systems that depend on remote access.
Exposure outlook
The available material does not include a regional measurement for Latin America or confirmed local cases, but it does show a clear risk pattern in technology used as an entry point into corporate networks. In practice, the priority signaled by CISA KEV, EPSS, and reports of active exploitation falls on teams that manage perimeter services, remote access, and platforms with sensitive credentials.
Sources
- June 2026 Threat Report: Actively Exploited CVEsgreenbone.net· Greenbone Networks
- Vulnerability Database — EPSS, CISA KEV & exploit statuso3.security· o3.security
- Resumen vulnerabilidades críticas – 27 elementos (09 jul 2026 Europe/Madrid)blog.iurlek.com· Iurlek Blog
- Actividad Maliciosa Activa en GlobalProtect y Nuevos CVEs en Infraestructura Perimetral de Palo Altodevel.group· Devel Group
- June 2026 CVEs: 57 Actively Exploited, Patch Exposed Assets Firstwindowsforum.com· WindowsForum (Recorded Future summary)
- HackerStorm Vulnerability Priority Report – June 2026hackerstorm.com· HackerStorm
- June 2026 Patch Tuesday: Updates and Analysiscrowdstrike.com· CrowdStrike



