What happened
Ivanti disclosed two critical vulnerabilities in Ivanti Sentry, its secure mobile gateway appliance, on June 9, 2026. Both allow a remote, unauthenticated attacker to fully compromise an affected device, and one was already showing signs of active exploitation before the week was out.
CVE-2026-10520 is an OS command injection flaw with a CVSS score of 10.0, the maximum possible rating. It lets an attacker execute code as root without providing any credentials. CVE-2026-10523, rated 9.9, is an authentication bypass that allows an unauthenticated attacker to create arbitrary administrative accounts and take full control of the appliance's management interface.
The affected versions are Ivanti Sentry 10.5.1, 10.6.1, 10.7.0 and earlier. Ivanti has released fixed builds in versions 10.5.2, 10.6.2 and 10.7.1, published alongside its advisory on the Ivanti Support Hub.
Why this one moved fast
Two days after disclosure, on June 11, 2026, CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation in the wild. The agency's binding operational directive gave federal civilian agencies until June 14, 2026, a three-day window, to apply the patch or take the appliance offline.
Researchers who reviewed the flaw after disclosure noted that a proof-of-concept was circulating publicly within roughly 24 hours, which shortened the gap between advisory and exploitation considerably compared with a typical patch cycle. Ivanti Sentry appliances sit at the network edge, managing mobile device traffic for the ActiveSync and other protocols, so a root-level compromise gives an attacker a foothold with reach into whatever backend systems the gateway is configured to talk to.
This masthead is not naming or speculating about who is behind the observed exploitation. Neither Ivanti's advisory nor CISA's KEV entry attributes the activity to a specific group, and no attribution has been independently confirmed at time of writing.
What Ivanti and CISA are telling customers
Ivanti's advisory recommends applying the patched builds immediately and, for organizations that cannot patch right away, restricting management-plane access to the Sentry appliance from untrusted networks as an interim measure. The company said it found no evidence of exploitation of CVE-2026-10523 at the time of disclosure, distinguishing it from CVE-2026-10520, which was already under active attack.
CISA's directive applies formally only to federal civilian executive branch agencies, but the agency's standard guidance to all organizations running affected software is to treat KEV entries as a signal to patch on an accelerated timeline rather than during the next scheduled maintenance window. Security vendors that track exposure of internet-facing Ivanti Sentry instances have flagged the appliance as a repeat target: Ivanti's edge products, including Sentry and its Endpoint Manager Mobile line, have been the subject of multiple KEV additions over the past two years.
The pattern this fits
Ivanti Sentry, formerly sold as MobileIron Sentry before Ivanti's rebrand, is one of several edge-facing enterprise appliances that have drawn sustained attacker interest because they are internet-exposed by design and often run with elevated privileges to manage device fleets. The compressed timeline here, disclosure to KEV addition in two days and to a public proof-of-concept in roughly one, is consistent with what security teams have reported across other appliance-class vulnerabilities disclosed this year: the window between an advisory going public and opportunistic scanning beginning has continued to shrink.
For IT and security teams running Sentry, the practical takeaway is straightforward. Confirm which build is deployed, apply 10.5.2, 10.6.2 or 10.7.1 as appropriate, and check outbound and management-plane logs for signs of compromise predating the patch, since a root-level command injection flaw can leave a foothold that a version upgrade alone does not remove.
Sources: Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) — Ivanti · CISA Adds One Known Exploited Vulnerability to Catalog — CISA · CVE-2026-10520, CVE-2026-10523 — Multiple critical vulnerabilities affecting Ivanti Sentry — Rapid7 · U.S. CISA adds Ivanti Sentry flaw to KEV catalog — Security Affairs · Max-Severity Ivanti Sentry Flaw Exploited Within 24 Hours — Dark Reading · Critical Ivanti Sentry flaw allows root-level remote code execution — Help Net Security
