logo

CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release

ID: ef6cf8ba-5b62-5510-9110-c2ff98e10c4a

STIX ID: report--ef6cf8ba-5b62-5510-9110-c2ff98e10c4a

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: Pierluigi Paganini

...
...

Attackers are actively exploiting CVE-2026-10520, a critical OS command injection in Ivanti Sentry allowing unauthenticated root remote code execution. Shadowserver observed exploitation attempts and several internet-exposed Sentry gateways backdoored shortly after patches were released, increasing risk to enterprise networks that rely on these gateways.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.