Internet-Facing Sentry Appliances Become Trust-Boundary Footholds

Ivanti Sentry is not just a vulnerable gateway here. It sits in front of corporate email, apps, and content, so unauthenticated root command execution turns the appliance itself into the compromise point on the trust boundary. FortiGuard says it is already seeing exploitation attempts for CVE-2026-10520 after public technical details and a PoC lowered the bar for opportunistic scanning. The flaw affects Ivanti Sentry 10.5.1 and earlier, 10.6.1 and earlier, and 10.7.0 and earlier, with fixes in 10.5.2, 10.6.2, and 10.7.1. The hard part is what may already be on the box. FortiGuard tells operators to assume exposed, unpatched appliances may be compromised, which means root access, rogue admin changes, persistence, and stolen credentials or tokens can outlive the patch.

Part of the PlainSec briefing for 2026-07-04

Sources