VYPR
Critical severity10.0CISA KEVNVD Advisory· Published Jun 9, 2026· Updated Jun 12, 2026

CVE-2026-10520

CVE-2026-10520

Description

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*range: <10.5.2
    • cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
  • Ivanti/Sentryllm-fuzzy
    Range: < R10.5.2, < R10.6.2, < R10.7.1

Patches

Vulnerability mechanics

References

2

News mentions

20