CVE-2026-10520
Ivanti Sentry OS Command Injection Vulnerability
Description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Description as published by the source, in English.
Key facts
- Published
- 2026-06-09
- Last modified
- 2026-07-23
- Assigned by
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Scored by
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- Probability of exploitation
-
99.9 %
among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Yes, see references
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-11, with a remediation deadline of 2026-06-14 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Ivanti | Standalone Sentry | < 10.5.2 | Affected |
| Ivanti | Standalone Sentry | 10.7.0 | Affected |
| Ivanti | Standalone Sentry | ≥ 10.6.0, < 10.6.2 | Affected |
Weakness type
-
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS …
References
- https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-…
- https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-1…
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520
Related at Berigo
Articles
-
CISA adds eight exploited vulnerabilities to its KEV catalogue
Same product
2026-03-09
Over five days CISA added eight flaws to its Known Exploited Vulnerabilities catalogue, spanning Hikvision, Rockwell, Apple, SolarWinds and Ivanti.
-
Ivanti EPMM vulnerabilities exploited against Dutch agencies
Same product
2026-02-06
The Dutch data protection authority and judiciary council confirm intrusions via Ivanti EPMM, while the European Commission investigates an incident …
-
Two Ivanti EPMM zero-days exploited in attacks
Same product
2026-01-29
Ivanti reports CVE-2026-1281 and CVE-2026-1340 in Endpoint Manager Mobile, exploited as zero-days. A patch is expected later in the first quarter.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.