A maximum-severity OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry is now being actively exploited in the wild, just one day after Ivanti released patches. The flaw allows attackers to execute code with root privileges on internet-exposed Sentry gateways. Shadowserver reports observing widespread exploitation attempts based on a public PoC, with at least 2 confirmed backdoored instances out of 19 detected — and warns that all unpatched instances should be considered compromised. Ivanti's advisory has not yet been updated to reflect active exploitation. This follows a pattern of Ivanti products being repeatedly targeted, with CISA having flagged 34 Ivanti vulnerabilities as actively exploited over recent years.
Table of contents
Related Articles:182 Impressions