logo

CISA orders feds to patch actively exploited Ivanti flaw by Sunday

ID: 0fbfbea8-1e11-5977-975b-a877802c88ba

STIX ID: report--0fbfbea8-1e11-5977-975b-a877802c88ba

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Sergiu Gatlan

...
...

CISA has ordered federal agencies to urgently patch a maximum-severity OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry (formerly MobileIron Sentry) after reports and vendor patches; Shadowserver and other observers report active exploitation and backdoored Internet-exposed gateways, and CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated remediation under Binding Operational Directive 26-04.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.