# Three Enterprise Titans Patch Critical Remote Code Execution Flaws—Urgent Updates Required
## The Threat
Enterprise infrastructure just got significantly more dangerous. On June 10, 2026, Fortinet, Ivanti, and SAP simultaneously disclosed nine critical vulnerabilities—including two that carry CVSS scores of 10.0 and 9.9—that allow unauthenticated attackers to execute arbitrary code and bypass authentication on some of the world's most mission-critical systems. These aren't theoretical risks: they're exploitable via HTTP requests, exist in widely deployed products, and require no special privileges to trigger.
The flaws span multiple attack vectors: command injection in Fortinet's malware sandbox appliances, OS command injection combined with authentication bypass in Ivanti's mobile security platform, and XML signature wrapping attacks paired with memory corruption in SAP's enterprise application servers and NetWeaver platform. What ties them together is their severity and the populations they expose—these are systems protecting enterprise networks, authenticating users, and running core business processes.
Most concerning is the sheer breadth of the patch set. A single organization running Ivanti Sentry, SAP NetWeaver, and Fortinet FortiSandbox—not an unusual configuration for large enterprises—now faces a compressed patching window on three critical systems simultaneously. The vendors have provided patches, but no evidence of in-the-wild exploitation yet. That window won't stay open for long.
## Severity and Impact
| Vendor | CVE | Product | CVSS Score | Vector | CWE | Auth Required |
|--------|-----|---------|------------|--------|-----|---|
| Fortinet | CVE-2026-25089 | FortiSandbox WEB UI | 9.1 | Network/Adjacent/None | CWE-78 (OS Command Injection) | No |
| Ivanti | CVE-2026-10520 | Ivanti Sentry | 10.0 | Network/Adjacent/None | CWE-78 (OS Command Injection) | No |
| Ivanti | CVE-2026-10523 | Ivanti Sentry | 9.9 | Network/Adjacent/None | CWE-287 (Auth Bypass) | No |
| SAP | CVE-2026-44748 | NetWeaver AS ABAP / ABAP Platform | 9.9 | Network/Low/None | CWE-347 (XML Signature Wrapping) | No |
| SAP | CVE-2026-27671 | NetWeaver / ABAP Platform | 9.8 | Network/Adjacent/None | CWE-119 (Memory Corruption) | No |
| SAP | CVE-2026-22732 | Commerce Cloud / Data Hub | 9.1 | Network/Low/None | CWE-89 (Spring Security) | Yes |
| SAP | CVE-2026-40128 | NetWeaver App Server Java | 9.0 | Network/Adjacent/Low | CWE-22 (Directory Traversal) | Yes |
## Affected Products
### Fortinet FortiSandbox
### Ivanti Sentry (formerly MobileIron Sentry)
### SAP NetWeaver & ABAP Platform
## Mitigations
Immediate actions:
1. Prioritize patching in this order: Ivanti Sentry (CVSS 10.0 unauthenticated RCE takes absolute priority), then Fortinet FortiSandbox, then SAP systems.
2. For Ivanti Sentry specifically: The patched version adds authentication controls that redirect unauthenticated requests to the vulnerable /mics/api/v2/sentry/mics-config/handleMessage endpoint to the login page. This is a defense-in-depth layer—if you cannot patch immediately, consider restricting network access to this endpoint to known administrative IP ranges.
3. For Fortinet FortiSandbox: Update affected versions immediately. The command injection vulnerability accepts specially crafted HTTP requests without authentication. Temporary mitigation: network segmentation and restricted access to the FortiSandbox WEB UI until patching is complete.
4. For SAP systems: Apply the patches for NetWeaver AS ABAP and ABAP Platform first (they carry the highest CVSS scores and the memory corruption flaw is especially dangerous). Commerce Cloud and Data Hub patches should follow. For organizations with complex SAP landscapes, coordinate with SAP support on a staged rollout plan to avoid disruptions to critical business processes.
5. General: Establish a patch management dashboard to track deployment across all three vendors. Do not assume all patches can deploy simultaneously—enterprise change management will likely require staggered schedules. Document which systems remain unpatched and the window of exposure.
## References
---
## HackWire Analysis
This coordinated disclosure reveals a critical vulnerability window in enterprise security infrastructure—and the vendors are moving faster than most organizations can patch. The 10.0 CVSS on Ivanti Sentry is nearly perfect-score severity: unauthenticated remote code execution as root on a platform designed to authenticate and control mobile devices enterprise-wide. An attacker exploiting this gains not just access to the Sentry appliance, but potential leverage over every mobile device managed by that platform.
The pattern here is worth noting. Three of the world's largest enterprise vendors—Fortinet (network/sandbox tier), Ivanti (identity/mobile tier), and SAP (application/backend tier)—all shipping critical unauthenticated RCE flaws on roughly the same timeline is not coincidence. This smells like Coordinated Disclosure (likely vendor-coordinated, possibly broker-coordinated), which means someone has had these exploits in reserve and is now releasing them into the wild all at once.
For organizations running SAP NetWeaver with Ivanti Sentry-managed devices protected by Fortinet FortiSandbox—a common enterprise architecture—this is a worst-case scenario. You're not just patching one system; you're coordinating updates across three different vendor stacks, three different change control processes, and three different timelines. The organization that manages this cleanly has mature patch management. Most don't.
The XML signature wrapping attack in SAP NetWeaver (CVE-2026-44748) is especially insidious: an attacker doesn't just execute code, they forge identity information in SAML exchanges, meaning they can impersonate legitimate users and gain access to sensitive data with the privileges of whoever they're impersonating. That's not lateral movement—that's privilege escalation baked into the authentication layer itself.
Defenders should assume that public exploit code for at least the Ivanti and Fortinet flaws will exist within 48 hours. Organizations that haven't patched within 5 business days should escalate to CISO and board level—the exposure window is too tight and the severity too high for standard patch cycles.
— HackWire Editorial
## Related Coverage