Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-10520

Published 2026-06-09
Updated 2 months ago
Vendor/s
Ivanti
Product/s
Sentry
Version/s
* > 10.5.2
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-10520 is a critical 10.0 CVSS command injection vulnerability in Ivanti Sentry allowing unauthenticated remote code execution.

CPE

Ivanti logo
Ivanti
Product Version Start Version End (excl.) Status
standalone_sentry * 10.5.2 vulnerable
standalone_sentry 10.6.0 10.6.2 vulnerable
standalone_sentry 10.7.0 10.7.0 vulnerable

Related weakness (CWE)

CWE-78

Remediation plan

1

Apply official patches

Immediately download and install the security updates provided by Ivanti for Sentry. Refer to the official Ivanti security advisory for CVE-2026-10520 to ensure all necessary hotfixes are applied to your environment.

2

Update affected systems

Ensure Ivanti Sentry is upgraded to version R10.5.2, R10.6.2, R10.7.1, or later. This addresses the command injection flaw present in versions prior to R10.5.2, the 10.6.x branch, and the 10.7.0 release.

3

Restrict access

Limit network exposure of the Ivanti Sentry management interface. Use firewalls or Access Control Lists (ACLs) to ensure it is not accessible from the public internet and restrict access to trusted administrative IP ranges only.

4

Monitor for exploitation

Review system logs for unusual shell command execution or unexpected outbound connections from Sentry appliances. Conduct forensic triage as per CISA BOD 26-04 requirements to identify potential indicators of compromise.

Detection Guidance

Detect exploitation by monitoring web server logs for suspicious characters associated with command injection, such as semicolons, ampersands, or backticks within HTTP requests. Look for unauthorized processes running with root privileges or unexpected modifications to system configuration files. Security teams should also inspect network traffic for reverse shell signatures or unusual data exfiltration patterns originating from the Sentry appliance toward unknown external IP addresses.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management