← Vulnerability feed

Vulnerability record · CVE-2026-10520 · published 9 June 2026

CVE-2026-10520: Ivanti Sentry OS command injection allows unauthenticated root RCE

Ivanti · Standalone Sentry

Ivanti Sentry before R10.5.2, R10.6.2 and R10.7.1 contains an OS command injection flaw (CWE-78) that lets a remote unauthenticated user execute commands at root level. It is remotely reachable over the network with no privileges or user interaction, and it is listed in CISA KEV, making it a top remediation priority.

10.0 CVSS 3.1 Critical CISA KEV since 11 Jun 2026 EPSS 100% · top 0.1% CWE-78 · OS command injection
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
23 Jul 2026Last modified by NVD

Description

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable root RCE with a CVSS score of 10, KEV listing and near-certain EPSS probability makes this an immediate patch-or-isolate case.

What it is

Ivanti Sentry before R10.5.2, R10.6.2 and R10.7.1 contains an OS command injection flaw (CWE-78) that lets a remote unauthenticated user execute commands at root level. It is remotely reachable over the network with no privileges or user interaction, and it is listed in CISA KEV, making it a top remediation priority.

Impact

An attacker gains root-level remote code execution on the Sentry appliance, allowing full control of the device, its configuration and any data or credentials it handles. Because no authentication is required, any internet-exposed instance is directly at risk.

Attack surface

Reached over the network via the vulnerable Sentry interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is needed, so any reachable instance is exposed.

Exploitation

CVE-2026-10520 is in CISA KEV (added 2026-06-11) and has an EPSS 30-day probability of 0.99915 (99.968th percentile), indicating active exploitation is expected or observed. A public third-party proof-of-concept reference exists, and no ransomware use is documented.

What to do

  • Upgrade Ivanti Sentry to R10.5.2, R10.6.2 or R10.7.1 or later per the vendor advisory.
  • If patching is not immediately possible, apply the vendor's mitigations or take the appliance off the internet until it is fixed.
  • Restrict network access to Sentry management and service interfaces to trusted sources only.
  • Follow CISA BOD 26-04 guidance, including the KEV due date of 2026-06-14, and discontinue use if mitigations are unavailable.
  • Rotate credentials and secrets stored or processed by Sentry after remediation, since root compromise may have exposed them.

Detection

  • Review Sentry and host logs for unexpected command execution, shell child processes, or anomalous outbound connections from the appliance.
  • Hunt for exploitation attempts against Sentry interfaces in web, proxy and IDS/IPS logs, using the public PoC reference for request patterns.
  • Monitor for new or modified files, cron jobs, and unauthorized accounts on Sentry hosts that would indicate post-exploitation persistence.
  • Alert on Sentry appliances still running versions below R10.5.2, R10.6.2 or R10.7.1.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-10520 to the Known Exploited Vulnerabilities catalog on 11 June 2026 as "Ivanti Sentry OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-10520 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-10523Ivanti Sentry authentication bypass allows admin account creationIvanti Sentry contains an authentication bypass (CWE-288, alternate path) that lets a remote, unauthenticated attacker create arbitrary administrativ…EPSS 53%analysed8.8CVE-2023-41724Ivanti standalone sentry command injection vulnerabilityA command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin…EPSS 13%5.5CVE-2024-8540Ivanti standalone sentry incorrect permission assignment vulnerabilityInsecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio…EPSS 0.25%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2026-10520), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.