Max severity Ivanti Sentry vulnerability now exploited in attacks
ID: 5b0fe0cd-84eb-55ec-8e9c-1ef540aad42c
STIX ID: report--5b0fe0cd-84eb-55ec-8e9c-1ef540aad42c
Feed Name: Bleeping Computer
Threat Score
Ivanti Sentry (formerly MobileIron Sentry) is affected by a maximum-severity OS command injection vulnerability (CVE-2026-10520) that allows remote code execution with root privileges; Ivanti released patches in Sentry R10.5.2, R10.6.2, and R10.7.1. Although Ivanti initially reported no known exploitation at disclosure, Shadowserver observed exploitation and multiple backdoored Internet-exposed Sentry instances, warning that unpatched systems are likely compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
