• News/
  • bleepingcomputer-20260611062022

Max severity Ivanti Sentry vulnerability now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 11, 2026
·
Updated

Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. Formerly known as MobileIron Sentry, the Ivanti Sentry security gateway appliance secures traffic between back-end corporate systems and remote mobile devices. Tracked as CVE-2026-10520, the maximum-severity vulnerability stems from an OS command injection weakness and was patched by Ivanti on Tuesday with the release of Sentry versions R10.5.2, R10.6.2, and R10.7.1. While the company said at the time that it had no evidence of in-the-wild exploitation, the Shadowserver nonprofit security organization reported the next day that attackers had already backdoored most of the Sentry gateways exposed online. The Internet security watchdog also added that, while its scans detect only a very limited number of exposed Sentry instances, there are likely more due to its search engine being blocklisted. "We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi NCA for the tip!). However, all remaining likely compromised too," Shadowserver warned. "While our detection is on the lowish side due to multiple Ivanti Sentry instances not reachable in our scans (blocklisted?), if you have not patched now you are most likely compromised." Ivanti has yet to update t...

Read full article

Affected Software

3 affected components
Ivanti Sentry<R10.5.2
Ivanti Sentry<R10.6.2
Ivanti Sentry<R10.7.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Ivanti Sentry that is now being actively exploited by attackers.

2

What security implications are discussed in the article?

The article highlights the potential for attackers to execute code with root privileges on Internet-exposed secure mobile gateways due to the vulnerability.

3

What products or software are affected by the vulnerability?

The affected product is Ivanti Sentry, formerly known as MobileIron Sentry.

4

What is the severity level of the Ivanti Sentry vulnerability?

The vulnerability is classified as maximum severity.

5

When was this vulnerability published and when was it exploited?

The vulnerability was published on June 11, 2026, and exploitation began shortly thereafter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203