CISA orders feds to patch actively exploited Ivanti flaw by Sunday
ID: 0fbfbea8-1e11-5977-975b-a877802c88ba
STIX ID: report--0fbfbea8-1e11-5977-975b-a877802c88ba
Feed Name: Bleeping Computer
Threat Score
CISA has ordered federal agencies to urgently patch a maximum-severity OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry (formerly MobileIron Sentry) after reports and vendor patches; Shadowserver and other observers report active exploitation and backdoored Internet-exposed gateways, and CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated remediation under Binding Operational Directive 26-04.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
