logo

Max severity Ivanti Sentry vulnerability now exploited in attacks

ID: 5b0fe0cd-84eb-55ec-8e9c-1ef540aad42c

STIX ID: report--5b0fe0cd-84eb-55ec-8e9c-1ef540aad42c

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Sergiu Gatlan

...
...

Ivanti Sentry (formerly MobileIron Sentry) is affected by a maximum-severity OS command injection vulnerability (CVE-2026-10520) that allows remote code execution with root privileges; Ivanti released patches in Sentry R10.5.2, R10.6.2, and R10.7.1. Although Ivanti initially reported no known exploitation at disclosure, Shadowserver observed exploitation and multiple backdoored Internet-exposed Sentry instances, warning that unpatched systems are likely compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.