SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-10520 2026-06-11

Ivanti Sentry CVE-2026-10520: Unauthenticated Root RCE Added to CISA KEV

"Ivanti Sentry contains a critical OS command injection flaw (CVSS 10.0) that lets a remote, unauthenticated attacker achieve root-level remote code execution, and CISA has added it to the Known Exploited Vulnerabilities…"

Ivanti Sentry contains a critical OS command injection flaw (CVSS 10.0) that lets a remote, unauthenticated attacker achieve root-level remote code execution, and CISA has added it to the Known Exploited Vulnerabilities catalog.

What Is It

CVE-2026-10520 is an OS command injection vulnerability (CWE-78) in Ivanti Sentry, formerly known as MobileIron Sentry. It allows a remote unauthenticated user to achieve root-level remote code execution. The flaw carries a CVSS 3.1 base score of 10.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges or user interaction required, with a changed scope and high confidentiality, integrity, and availability impact.

Why It Matters

Root-level RCE without authentication is the highest-severity outcome a remote vulnerability can produce. CISA added CVE-2026-10520 to its KEV catalog on 2026-06-11. The catalog inclusion confirms it is exploited in the wild; known ransomware campaign use is listed as Unknown. The condition for successful exploitation is an Ivanti Sentry appliance in an unmanaged state with its endpoints externally reachable. Using mTLS with EPMM, or restricting HTTPS access through Neurons for MDM, makes those interfaces inaccessible to external actors.

What's Vulnerable

Ivanti Sentry (formerly MobileIron Sentry) before versions R10.5.2, R10.6.2, and R10.7.1 is affected. Appliances most at risk are those in an unmanaged state with externally reachable endpoints. No affected CPEs were enumerated in the NVD record at time of writing.

Patch Status

CISA's required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance and CISA's "Forensics Triage Requirements." Where mitigations are unavailable, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. The due date is 2026-06-14. Fixed versions are R10.5.2, R10.6.2, and R10.7.1.

Sources