Overdue Patch Follows AI-Found Sentry Command Injection

Ivanti’s own security workflow found a flaw that can give an unauthenticated internet user root-level command execution on Sentry, so this is a normal critical gateway patch item first and an AI story second. The vendor says the bug is CVE-2026-10520, scored 10.0, and the remediation deadline is already past, which turns it into overdue exposure rather than a fresh disclosure to watch. The flaw affected Ivanti Sentry, and Ivanti says an LLM helped identify and remediate it because the issue had escaped traditional tooling. Ivanti has fixed versions in R10.5.2, R10.6.2, and R10.7.1, and the bigger signal is that LLM-assisted review is now producing concrete vendor fixes for high-impact bugs that humans and standard scanners missed.

Part of the PlainSec briefing for 2026-07-21

Sources