securityaffairs.com 6/12/2026, 7:51:43 PM · external

CISA urges immediate patch for Ivanti Sentry CVE-2026-10520 flaw

CISA urges immediate patch for Ivanti Sentry CVE-2026-10520 flaw
Developing story vulnerability 13 articles tracked
Ivanti Sentry OS command injection flaw (CVE-2026-10520) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Ivanti Sentry, identified as CVE-2026-10520, to its Known Exploited Vulnerabilities catalog, urging immediate patching by June 14, 2026. This vulnerability, with a CVSS score of 10.0, allows remote code execution with root privileges due to an OS command injection flaw.

Although Ivanti initially reported no active exploitation, researchers have observed attempts at exploitation shortly after a security patch was released, with many exposed Sentry gateways being compromised. CISA mandates federal agencies to address this vulnerability to enhance network security.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline