www.securityweek.com 6/12/2026, 10:11:03 AM · external

Ivanti Sentry Exploitation Attempts Hitting Honeypots

Ivanti Sentry Exploitation Attempts Hitting Honeypots
Developing story vulnerability 12 articles tracked
Ivanti Sentry OS command injection flaw (CVE-2026-10520) exploited in the wild
CyberSIXT Evidence Panel
Primary Source hub.ivanti.com
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE US Cybersecurity and Infrastructure Security Agency (CISA) has flagged a recently patched Ivanti Sentry vulnerability (CVE-2026-10520) with a critical CVSS score of 10/10, identified as an OS command injection that can be exploited remotely to execute arbitrary code with root privileges. Although Ivanti has issued patches and claims there is no evidence of actual exploitation, CISA included it in its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to address it within three days. Ivanti indicates the risk depends on proper configuration, urging users to avoid exposing management interfaces to the internet.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline