CVE-2026-10520 is a critical 10.0 CVSS command injection vulnerability in Ivanti Sentry allowing unauthenticated remote code execution.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| standalone_sentry | * | 10.5.2 | vulnerable |
| standalone_sentry | 10.6.0 | 10.6.2 | vulnerable |
| standalone_sentry | 10.7.0 | 10.7.0 | vulnerable |
Immediately download and install the security updates provided by Ivanti for Sentry. Refer to the official Ivanti security advisory for CVE-2026-10520 to ensure all necessary hotfixes are applied to your environment.
Ensure Ivanti Sentry is upgraded to version R10.5.2, R10.6.2, R10.7.1, or later. This addresses the command injection flaw present in versions prior to R10.5.2, the 10.6.x branch, and the 10.7.0 release.
Limit network exposure of the Ivanti Sentry management interface. Use firewalls or Access Control Lists (ACLs) to ensure it is not accessible from the public internet and restrict access to trusted administrative IP ranges only.
Review system logs for unusual shell command execution or unexpected outbound connections from Sentry appliances. Conduct forensic triage as per CISA BOD 26-04 requirements to identify potential indicators of compromise.
Detect exploitation by monitoring web server logs for suspicious characters associated with command injection, such as semicolons, ampersands, or backticks within HTTP requests. Look for unauthorized processes running with root privileges or unexpected modifications to system configuration files. Security teams should also inspect network traffic for reverse shell signatures or unusual data exfiltration patterns originating from the Sentry appliance toward unknown external IP addresses.
Experience superior visibility and a simpler approach to cyber risk management