Vulnerabilities & Exploits

Overdue Patch Follows AI-Found Sentry Command Injection

Ivanti’s own security workflow found a flaw that can give an unauthenticated internet user root-level command execution on Sentry, so this is a normal critical gateway patch item first and an AI story second. The vendor says the bug is CVE-2026-10520, scored 10.0, and the remediation deadline is already past, which turns it into overdue exposure rather than a fresh disclosure to watch.

The flaw affected Ivanti Sentry, and Ivanti says an LLM helped identify and remediate it because the issue had escaped traditional tooling. Ivanti has fixed versions in R10.5.2, R10.6.2, and R10.7.1, and the bigger signal is that LLM-assisted review is now producing concrete vendor fixes for high-impact bugs that humans and standard scanners missed.

1 source · Jul 20

CVE-2026-10520

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…

CISA federal remediation date Jun 14 · date passed

Timeline

Sources

Vendor digest: Ivanti

Part of the PlainSec briefing for 2026-07-20

Every edition of this story: Overdue Patch Follows AI-Found Sentry Command Injection

More from today