A maximum-severity OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry is now being actively exploited in the wild, just one day after Ivanti released patches. The flaw allows attackers to execute code with root privileges on internet-exposed Sentry gateways. Shadowserver reports observing widespread exploitation attempts based on a public PoC, with at least 2 confirmed backdoored instances out of 19 detected — and warns that all unpatched instances should be considered compromised. Ivanti's advisory has not yet been updated to reflect active exploitation. This follows a pattern of Ivanti products being repeatedly targeted, with CISA having flagged 34 Ivanti vulnerabilities as actively exploited over recent years.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
182 Impressions