Critical severity10.0CISA KEVNVD Advisory· Published Jun 9, 2026· Updated Jun 12, 2026
CVE-2026-10520
CVE-2026-10520
Description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*range: <10.5.2
- cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523nvdPatchVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
20- Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation PushDark Reading · Jul 20, 2026
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposThe Hacker News · Jul 2, 2026
- ChocoPoc malware delivered via trojanized exploits on GitHubBleepingComputer · Jul 1, 2026
- New ChocoPoC malware targets researchers via trojanized PoC exploitsBleepingComputer · Jul 1, 2026
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHelp Net Security · Jun 14, 2026
- Ivanti Sentry Exploitation Attempts Hitting HoneypotsSecurityWeek · Jun 12, 2026
- CISA orders feds to patch actively exploited Ivanti flaw by SundayBleepingComputer · Jun 12, 2026
- Max-Severity Ivanti Flaw Exploited 24 Hours After DisclosureDark Reading · Jun 11, 2026
- Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC ReleaseCyber Security News · Jun 11, 2026
- Max severity Ivanti Sentry vulnerability now exploited in attacksBleepingComputer · Jun 11, 2026
- Ivanti: Actively-Exploited Flaw CVE-2026-10520 Added to CISA KEVVypr Intelligence · Jun 11, 2026
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesThe Hacker News · Jun 10, 2026
- Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)Help Net Security · Jun 10, 2026
- Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9The Register Security · Jun 10, 2026
- CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti SentryRapid7 Blog · Jun 10, 2026
- Critical Vulnerabilities Patched in Fortinet, Ivanti ProductsSecurityWeek · Jun 10, 2026
- Ivanti: Max severity Sentry flaw allows code execution as rootBleepingComputer · Jun 10, 2026
- More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)watchTowr Labs · Jun 10, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts