---
title: "Max severity Ivanti Sentry vulnerability now exploited in attacks"
url: https://daily.dev/posts/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks-17nw2pxpe
source_url: https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks
type: article
source: "BleepingComputer"
published: 2026-06-11T06:22:37.639Z
updated: 2026-06-11T06:23:05.360Z
tags: ["security"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Max severity Ivanti Sentry vulnerability now exploited in attacks

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A maximum-severity OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry is now being actively exploited in the wild, just one day after Ivanti released patches. The flaw allows attackers to execute code with root privileges on internet-exposed Sentry gateways. Shadowserver reports observing widespread exploitation attempts based on a public PoC, with at least 2 confirmed backdoored instances out of 19 detected — and warns that all unpatched instances should be considered compromised. Ivanti's advisory has not yet been updated to reflect active exploitation. This follows a pattern of Ivanti products being repeatedly targeted, with CISA having flagged 34 Ivanti vulnerabilities as actively exploited over recent years.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks>

## Similar posts on daily.dev

- [Ivanti: Max severity Sentry flaw allows code execution as root](https://daily.dev/posts/ivanti-max-severity-sentry-flaw-allows-code-execution-as-root-h8hixzuel) · BleepingComputer · 0 upvotes · 0 comments
- [CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry](https://daily.dev/posts/cve-2026-10520-cve-2026-10523---multiple-critical-vulnerabilities-affecting-ivanti-sentry-uxvwlkgex) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments
- [Ivanti patches critical Sentry flaws that lead to full device takeover](https://daily.dev/posts/ivanti-patches-critical-sentry-flaws-that-lead-to-full-device-takeover-uuwutwn8p) · CSO Online · 0 upvotes · 0 comments
- [CISA orders feds to patch actively exploited Ivanti flaw by Sunday](https://daily.dev/posts/cisa-orders-feds-to-patch-actively-exploited-ivanti-flaw-by-sunday-f8lysw95b) · BleepingComputer · 0 upvotes · 0 comments
- [Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9](https://daily.dev/posts/ivanti-tells-sentry-customers-to-patch-now-as-critical-bugs-hit-10-0-and-9-9-f3ulvlxlq) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks-17nw2pxpe)
