UPDATE Threat actors pounced on a critical Ivanti Sentry vulnerability within 24 hours of its disclosure, using a public proof-of-concept (PoC) exploit in attacks. Ivanti disclosed Tuesday CVE-2026-10520, an OS command injection vulnerability that affects the company's Sentry mobile gateway product prior to versions R10.5.2, R10.6.2 and R10.7.1. The vulnerability, which received a maximum severity CVSS score of 10, enables an unauthenticated attacker to remotely execute code with root privileges. Ivanti disclosed the flaw along with another Sentry vulnerability, CVE-2026-10523, an authentication bypass flaw with a 9.9 CVSS score. In its security advisory, Ivanti initially said it was unaware of either flaw being exploited in the wild. But the situation apparently changed very quickly for CVE-2026-10520. Cybersecurity vendor WatchTowr yesterday published a technical analysis of the flaw along with a PoC exploit. In a blog post the same day, Rapid7 warned the flaw is easy to weaponize and urged organizations to take immediate action. "Given the trivial nature of exploitation and the availability of a public PoC, exploitation in-the-wild is likely to begin," Rapid7 researchers wrote. "Organizations running affected versions of Ivanti Sentry should remediate these issues on an urgent basis before exploitation in-the-wild begins." Sure enough, attackers jumped on CVE-2026-10520 soon after. In a post on social media platform Mastodon, the Shadowserver Foundation said it observed "a...
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Dark Reading
·Rob Wright
·Published Jun 11, 2026
·Updated
Affected Software
1 affected component
Ivanti Sentry<R10.5.2, <R10.6.2, <R10.7.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the rapid exploitation of a critical vulnerability in Ivanti Sentry software shortly after its disclosure.
2
What specific vulnerability is highlighted in the article?
The vulnerability highlighted is CVE-2026-10520, which is an OS command injection flaw affecting Ivanti Sentry.
3
How soon after disclosure was the Ivanti vulnerability exploited?
The Ivanti vulnerability was exploited within 24 hours of its public disclosure.
4
What type of attack method is being used by threat actors according to the article?
Threat actors are using a public proof-of-concept exploit to execute attacks on the Ivanti Sentry vulnerability.
5
Which product is specifically affected by the CVE-2026-10520 vulnerability?
The affected product is the Ivanti Sentry mobile gateway.