Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. Formerly known as MobileIron Sentry, the Ivanti Sentry security gateway appliance secures traffic between back-end corporate systems and remote mobile devices. Tracked as CVE-2026-10520, the maximum-severity vulnerability stems from an OS command injection weakness and was patched by Ivanti on Tuesday with the release of Sentry versions R10.5.2, R10.6.2, and R10.7.1. While the company said at the time that it had no evidence of in-the-wild exploitation, the Shadowserver nonprofit security organization reported the next day that attackers had already backdoored most of the Sentry gateways exposed online. The Internet security watchdog also added that, while its scans detect only a very limited number of exposed Sentry instances, there are likely more due to its search engine being blocklisted. "We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi NCA for the tip!). However, all remaining likely compromised too," Shadowserver warned. "While our detection is on the lowish side due to multiple Ivanti Sentry instances not reachable in our scans (blocklisted?), if you have not patched now you are most likely compromised." Ivanti has yet to update t...
Max severity Ivanti Sentry vulnerability now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Jun 11, 2026
·Updated
Affected Software
3 affected components
Ivanti Sentry<R10.5.2
Ivanti Sentry<R10.6.2
Ivanti Sentry<R10.7.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Ivanti Sentry that is now being actively exploited by attackers.
2
What security implications are discussed in the article?
The article highlights the potential for attackers to execute code with root privileges on Internet-exposed secure mobile gateways due to the vulnerability.
3
What products or software are affected by the vulnerability?
The affected product is Ivanti Sentry, formerly known as MobileIron Sentry.
4
What is the severity level of the Ivanti Sentry vulnerability?
The vulnerability is classified as maximum severity.
5
When was this vulnerability published and when was it exploited?
The vulnerability was published on June 11, 2026, and exploitation began shortly thereafter.