Ivanti released emergency security updates for its Sentry mobile gateway after finding two critical flaws that could let attackers take over affected systems. The bugs are CVE-2026-10520, a maximum-severity OS command injection issue that can enable remote code execution as root, and CVE-2026-10523, an authentication bypass that can let unauthenticated attackers create rogue admin accounts. Fixes are in Sentry versions R10.5.2, R10.6.2, and R10.7.1; Ivanti said it has no evidence of active exploitation at disclosure.
Ionut Arghire
2026.06.12
95% relevant
This article updates the same Ivanti Sentry event by adding that CISA placed CVE-2026-10520 in the KEV catalog as exploited, while Ivanti says the observed activity was attempted exploitation against honeypots and reiterates exposure conditions around management port 8443, mTLS-protected deployments, and affected fixed versions 10.5.2, 10.6.2, and 10.7.1.
Sergiu Gatlan
2026.06.12
96% relevant
This advances the same underlying event by adding that CVE-2026-10520 is now confirmed as actively exploited, has been added to CISA's Known Exploited Vulnerabilities catalog, and is the first flaw subject to CISA's new Binding Operational Directive 26-04 with a three-day federal patch deadline.
Sergiu Gatlan
2026.06.11
97% relevant
This updates the same Ivanti Sentry event by adding that CVE-2026-10520 is now being exploited in the wild after patch release, that Shadowserver observed exploitation attempts and at least two internet-exposed Sentry instances backdoored, and that a public proof-of-concept is being used.
2026.06.10
99% relevant
This article reports the same Ivanti Sentry disclosure, adding patch urgency, affected fixed versions (10.5.2, 10.6.2, 10.7.1), and technical detail from watchTowr that CVE-2026-10520 involved an exposed Apache Tomcat API parsing attacker-controlled MICS configuration commands; it also reiterates CVE-2026-10523 as an unauthenticated admin-account creation flaw.
Ionut Arghire
2026.06.10
94% relevant
This article adds that Ivanti released Sentry 10.5.2, 10.6.2, and 10.7.1 to fix CVE-2026-10520 and CVE-2026-10523, and also notes related EPMM fixes (CVE-2026-6973 and CVE-2026-10727). It reiterates that CVE-2026-10520 is a remote unauthenticated OS command injection leading to root code execution and that CVE-2026-10523 is a remote unauthenticated authentication bypass allowing creation of administrator accounts, with Ivanti saying it has no evidence of active exploitation.
Sergiu Gatlan
2026.06.10
100% relevant
This article establishes a new tracked event: Ivanti's June 2026 disclosure and patching of CVE-2026-10520 and CVE-2026-10523 in Sentry, distinct from prior Ivanti EPMM and other zero-day stories.