Ivanti Sentry is facing active exploitation attempts following the public release of proof-of-concept (PoC) code targeting a critical OS command injection vulnerability tracked as CVE-2026-10520.
The flaw, along with a second critical issue (CVE-2026-10523), was disclosed by Ivanti on June 9, 2026, with both affecting multiple versions of the Sentry mobile device management gateway.
Although Ivanti stated in the disclosure that there was no evidence of active exploitation, threat intelligence from Shadowserver indicates that attackers quickly weaponized the PoC, triggering widespread scanning and compromise attempts across exposed systems.
CVE-2026-10520 is a remote, unauthenticated OS command injection vulnerability (CWE-78) with a maximum CVSS score of 10.0, allowing attackers to execute arbitrary commands with root-level privileges.
The flaw impacts Ivanti Sentry versions before 10.5.2, 10.6.2, and 10.7.1. Due to its network-exploitable nature requiring no authentication or user interaction, the vulnerability presents a highly attractive attack vector for opportunistic threat actors and botnet operators.
Security researchers warn that exploitation can lead to full system takeover, persistent deployment, and lateral movement within enterprise environments.
The second vulnerability, CVE-2026-10523, is an authentication bypass issue (CWE-288) with a CVSS score of 9.9. This flaw enables unauthenticated attackers to create arbitrary administrative accounts, effectively granting full control over the Sentry appliance.
When combined with CVE-2026-10520, attackers can gain privileged access and execute commands with impunity, significantly increasing the attack surface and impact severity.
Shortly after PoC code became publicly available, Shadowserver reported a surge in exploitation attempts observed in the wild. According to their telemetry, at least 19 vulnerable Ivanti Sentry instances were identified during internet-wide scans, with two confirmed as already backdoored.
Researchers further cautioned that the remaining exposed systems are highly likely to have been compromised, underscoring the rapid exploitation lifecycle often seen with critical edge-device vulnerabilities.
Ivanti has released patched versions addressing both vulnerabilities, including Sentry 10.5.2, 10.6.2, and 10.7.1. Organizations are strongly urged to upgrade immediately using official images available via the Ivanti download portal.
Given the nature of the vulnerabilities, patching alone may not be sufficient for systems already exposed. Security teams should perform thorough compromise assessments, including reviewing system logs, identifying unauthorised administrative accounts, and checking for indicators of persistence mechanisms such as web shells or modified configurations.
The vulnerabilities were responsibly disclosed, with Bryan Lam credited for reporting CVE-2026-10523. However, the rapid transition from disclosure to exploitation highlights ongoing risks associated with internet-facing enterprise appliances.
Ivanti Sentry, often deployed as a gateway for mobile and email traffic, represents a high-value target due to its position within enterprise infrastructure.
Security experts recommend immediate mitigation steps, including restricting external access to Sentry instances, applying patches without delay, and monitoring for suspicious network activity.
The incident once again reinforces the critical need for proactive vulnerability management, especially for edge devices that are frequently targeted within hours of public disclosure.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…