CVE-2026-10520
Known exploited · CISA KEV
CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…
CISA federal remediation date Jun 14 · date passed
Vulnerabilities · 73 days ago
Ivanti Sentry is not just a vulnerable gateway here. It sits in front of corporate email, apps, and content, so unauthenticated root command execution turns the appliance itself into the compromise point on the trust boundary.
FortiGuard says it is already seeing exploitation attempts for CVE-2026-10520 after public technical details and a PoC lowered the bar for opportunistic scanning. The flaw affects Ivanti Sentry 10.5.1 and earlier, 10.6.1 and earlier, and 10.7.0 and earlier, with fixes in 10.5.2, 10.6.2, and 10.7.1.
The hard part is what may already be on the box. FortiGuard tells operators to assume exposed, unpatched appliances may be compromised, which means root access, rogue admin changes, persistence, and stolen credentials or tokens can outlive the patch.
Known exploited · CISA KEV
CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…
CISA federal remediation date Jun 14 · date passed
1 source covering this story
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Vulnerability?FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of techn...
Part of the PlainSec briefing for 2026-07-04