CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
ID: 4af8473c-c2cd-571e-85c1-b479c369e313
STIX ID: report--4af8473c-c2cd-571e-85c1-b479c369e313
Feed Name: Security Affairs
Threat Score
Attackers are actively exploiting CVE-2026-10520, a critical OS command injection in Ivanti Sentry that allows unauthenticated remote root code execution. Shadowserver observed exploitation attempts and confirmed backdoored, internet-exposed Sentry gateways shortly after patch publication, raising immediate risk because compromised Sentry appliances grant access inside enterprise trusted boundaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
