Vulnerability record · CVE-2026-10520 · published 9 June 2026
CVE-2026-10520: Ivanti Sentry OS command injection allows unauthenticated root RCE
Ivanti · Standalone Sentry
Ivanti Sentry before R10.5.2, R10.6.2 and R10.7.1 contains an OS command injection flaw (CWE-78) that lets a remote unauthenticated user execute commands at root level. It is remotely reachable over the network with no privileges or user interaction, and it is listed in CISA KEV, making it a top remediation priority.
Description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable root RCE with a CVSS score of 10, KEV listing and near-certain EPSS probability makes this an immediate patch-or-isolate case.
What it is
Ivanti Sentry before R10.5.2, R10.6.2 and R10.7.1 contains an OS command injection flaw (CWE-78) that lets a remote unauthenticated user execute commands at root level. It is remotely reachable over the network with no privileges or user interaction, and it is listed in CISA KEV, making it a top remediation priority.
Impact
An attacker gains root-level remote code execution on the Sentry appliance, allowing full control of the device, its configuration and any data or credentials it handles. Because no authentication is required, any internet-exposed instance is directly at risk.
Attack surface
Reached over the network via the vulnerable Sentry interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is needed, so any reachable instance is exposed.
Exploitation
CVE-2026-10520 is in CISA KEV (added 2026-06-11) and has an EPSS 30-day probability of 0.99915 (99.968th percentile), indicating active exploitation is expected or observed. A public third-party proof-of-concept reference exists, and no ransomware use is documented.
What to do
- Upgrade Ivanti Sentry to R10.5.2, R10.6.2 or R10.7.1 or later per the vendor advisory.
- If patching is not immediately possible, apply the vendor's mitigations or take the appliance off the internet until it is fixed.
- Restrict network access to Sentry management and service interfaces to trusted sources only.
- Follow CISA BOD 26-04 guidance, including the KEV due date of 2026-06-14, and discontinue use if mitigations are unavailable.
- Rotate credentials and secrets stored or processed by Sentry after remediation, since root compromise may have exposed them.
Detection
- Review Sentry and host logs for unexpected command execution, shell child processes, or anomalous outbound connections from the appliance.
- Hunt for exploitation attempts against Sentry interfaces in web, proxy and IDS/IPS logs, using the public PoC reference for request patterns.
- Monitor for new or modified files, cron jobs, and unauthorized accounts on Sentry hosts that would indicate post-exploitation persistence.
- Alert on Sentry appliances still running versions below R10.5.2, R10.6.2 or R10.7.1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-10520 to the Known Exploited Vulnerabilities catalog on 11 June 2026 as "Ivanti Sentry OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US | PatchVendor Advisory |
| https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 | US Government Resource |
Track CVE-2026-10520 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-10520), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.