Vulnerabilities · 73 days ago

Internet-Facing Sentry Appliances Become Trust-Boundary Footholds

Ivanti Sentry is not just a vulnerable gateway here. It sits in front of corporate email, apps, and content, so unauthenticated root command execution turns the appliance itself into the compromise point on the trust boundary.

FortiGuard says it is already seeing exploitation attempts for CVE-2026-10520 after public technical details and a PoC lowered the bar for opportunistic scanning. The flaw affects Ivanti Sentry 10.5.1 and earlier, 10.6.1 and earlier, and 10.7.0 and earlier, with fixes in 10.5.2, 10.6.2, and 10.7.1.

The hard part is what may already be on the box. FortiGuard tells operators to assume exposed, unpatched appliances may be compromised, which means root access, rogue admin changes, persistence, and stolen credentials or tokens can outlive the patch.

CVE-2026-10520

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…

CISA federal remediation date Jun 14 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Ivanti

Part of the PlainSec briefing for 2026-07-04

Editions

Related stories