Skip to content
.ca
sign in
detection rulesuricata

IVANTI SENTRY CVE-2026-10520 MICS handleMessage POST (pre-auth RCE attempt)

First seen
2026-06-21
Last seen
2026-06-21
Used in
1 post
SuricataIVANTI SENTRY CVE-2026-10520 MICS handleMessage POST (pre-auth RCE attempt)
alert http $EXTERNAL_NET any -> $HOME_NET 8443 (msg:"IVANTI SENTRY CVE-2026-10520 MICS handleMessage POST (pre-auth RCE attempt)"; flow:to_server,established; http.method; content:"POST"; http.uri; content:"/mics/"; content:"/handleMessage"; fast_pattern; reference:cve,2026-10520; reference:url,nvd.nist.gov/vuln/detail/CVE-2026-10520; classtype:attempted-admin; priority:1; sid:1000844001; rev:1;)

Posts using this rule