Update June 15, 00:54 EDT: An Ivanti spokesperson told BleepingComputer that CISA added the flaw to its KEV catalog based on reports of attempted exploitation of honeypots. "While this CVE carries a CVSS score of 10, the risk posed to customers is decreased significantly based on deployment and configuration," the spokesperson added. "Successful exploitation requires access to the management port 8443 and this port should never be exposed to the internet. Honeypots often have misconfigurations to identify and track malicious behavior." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04. Tracked as CVE-2026-10520, this maximum-severity vulnerability was found in Ivanti's security gateway appliance (formerly known as MobileIron Sentry) and stems from an OS command injection weakness. On Wednesday, one day after Ivanti released patches for CVE-2026-10520 and said that it had no evidence of in-the-wild exploitation, the Shadowserver Internet security watchdog reported that attackers had already backdoored many of the Sentry gateways exposed online. While Shadowserver now tracks just over 50 Sentry admin portals exposed online, it says the number of Internet-exposed Ivanti Sentry instances it can detect is likely limited by organizations blocking its security scanner, and warns that systems that we...
CISA orders feds to patch actively exploited Ivanti flaw by Sunday
BleepingComputer
·Sergiu Gatlan
·Published Jun 12, 2026
·Updated
Affected Software
1 affected component
Ivanti Sentry (security gateway appliance)
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the urgent directive from CISA for federal agencies to patch a critical vulnerability in Ivanti software that is actively being exploited.
2
What security implications are discussed?
The article highlights a high-risk vulnerability with a CVSS score of 10 that has been actively exploited against Ivanti Sentry.
3
What products or software are affected?
The vulnerability affects Ivanti Sentry, which is a security gateway appliance.
4
What action has CISA mandated regarding the Ivanti flaw?
CISA has ordered federal agencies to patch the vulnerable Ivanti Sentry software by Sunday.
5
What does KEV stand for in the context of the article?
KEV stands for Known Exploited Vulnerabilities, indicating that this flaw is recognized as a current threat.