Ivanti has issued an urgent warning to customers regarding two critical vulnerabilities in its Ivanti Sentry product, a key component for mobile device management security. The most critical of these, CVE-2026-10520, is an OS command injection flaw that can be exploited by a remote, unauthenticated attacker to gain root-level control over the appliance. A second vulnerability, CVE-2026-10523, allows an attacker to bypass authentication and create new administrator accounts. Although Ivanti reports no active exploitation, security firm WatchTowr has publicly released technical details and a vulnerability scanner for CVE-2026-10520. This disclosure dramatically shortens the window for defenders to act before exploits are developed and deployed. A compromised Sentry appliance provides a gateway to backend corporate resources, including email and internal applications, making these vulnerabilities an immediate and critical threat.
CVE-2026-10520: This is a critical OS command injection vulnerability. Researchers at WatchTowr discovered that a specific API endpoint intended for internal configuration was exposed to the internet without requiring authentication. An attacker can send specially crafted commands to this endpoint, which are then executed on the underlying operating system with root privileges. This provides a direct path to full system compromise.CVE-2026-10523: This is an authentication bypass vulnerability. While fewer technical details are available, it reportedly allows an attacker to create new administrative accounts on the Sentry device. This could be used to establish persistence or as a stepping stone to further exploit the system.Chaining these two vulnerabilities could allow an attacker to gain full control, create persistent access, and then use the Sentry appliance's trusted position to pivot into the internal network.
The vulnerabilities affect the following versions of Ivanti Sentry (formerly MobileIron Sentry):
Ivanti has released patched versions 10.5.2, 10.6.2, and 10.7.1 to address these issues.
As of June 10, 2026, Ivanti has stated there is no evidence of these vulnerabilities being exploited in the wild. However, the public release of technical analysis and a scanning tool by WatchTowr makes exploitation highly likely in the near future. Threat actors are known to actively target vulnerabilities in edge devices like Ivanti products, often within hours or days of public disclosure.
The impact of exploiting these vulnerabilities is severe. The Ivanti Sentry appliance functions as a critical security gateway, mediating access between mobile devices (smartphones, tablets) and a company's backend resources like Microsoft Exchange Server and other internal applications. A successful attacker could:
Given its role as a trusted intermediary, a compromised Sentry device is a catastrophic security failure.
The following patterns may help identify vulnerable or compromised systems:
/mifs/services/config/CVE-2026-10520.CVE-2026-10523.bash, sh, nc, curl/mifs/services/config/ path from external IP addresses. This leverages D3FEND's Web Session Activity Analysis (D3-WSAA).CISA mandates federal agencies patch Ivanti Sentry flaw (CVE-2026-10520) within 3 days due to confirmed active exploitation and KEV catalog addition.
The critical Ivanti Sentry vulnerability, CVE-2026-10520, is now confirmed to be under active exploitation, leading the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog. CISA has issued an emergency directive requiring federal agencies to patch the flaw by June 15, 2026. Security researchers report widespread exploitation attempts against internet-exposed Sentry admin portals, warning that unpatched systems are likely already compromised. This significantly increases the urgency and severity of the threat, moving from potential to confirmed active attacks.
Ivanti releases patches and an advisory for critical vulnerabilities CVE-2026-10520 and CVE-2026-10523.
Security firm WatchTowr publishes technical details and a scanner for CVE-2026-10520.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.