• News/
  • darkreading-20260611184357

Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure

Dark Reading
·
Rob Wright
·
Published Jun 11, 2026
·
Updated

UPDATE Threat actors pounced on a critical Ivanti Sentry vulnerability within 24 hours of its disclosure, using a public proof-of-concept (PoC) exploit in attacks. Ivanti disclosed Tuesday CVE-2026-10520, an OS command injection vulnerability that affects the company's Sentry mobile gateway product prior to versions R10.5.2, R10.6.2 and R10.7.1. The vulnerability, which received a maximum severity CVSS score of 10, enables an unauthenticated attacker to remotely execute code with root privileges. Ivanti disclosed the flaw along with another Sentry vulnerability, CVE-2026-10523, an authentication bypass flaw with a 9.9 CVSS score. In its security advisory, Ivanti initially said it was unaware of either flaw being exploited in the wild. But the situation apparently changed very quickly for CVE-2026-10520. Cybersecurity vendor WatchTowr yesterday published a technical analysis of the flaw along with a PoC exploit. In a blog post the same day, Rapid7 warned the flaw is easy to weaponize and urged organizations to take immediate action. "Given the trivial nature of exploitation and the availability of a public PoC, exploitation in-the-wild is likely to begin," Rapid7 researchers wrote. "Organizations running affected versions of Ivanti Sentry should remediate these issues on an urgent basis before exploitation in-the-wild begins." Sure enough, attackers jumped on CVE-2026-10520 soon after. In a post on social media platform Mastodon, the Shadowserver Foundation said it observed "a...

Read full article

Affected Software

1 affected component
Ivanti Sentry<R10.5.2, <R10.6.2, <R10.7.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the rapid exploitation of a critical vulnerability in Ivanti Sentry software shortly after its disclosure.

2

What specific vulnerability is highlighted in the article?

The vulnerability highlighted is CVE-2026-10520, which is an OS command injection flaw affecting Ivanti Sentry.

3

How soon after disclosure was the Ivanti vulnerability exploited?

The Ivanti vulnerability was exploited within 24 hours of its public disclosure.

4

What type of attack method is being used by threat actors according to the article?

Threat actors are using a public proof-of-concept exploit to execute attacks on the Ivanti Sentry vulnerability.

5

Which product is specifically affected by the CVE-2026-10520 vulnerability?

The affected product is the Ivanti Sentry mobile gateway.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203