CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2026-06-11. EPSS: 99.9% chance of exploitation in the next 30 days.

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Affected products

  • Ivanti Standalone Sentry: before 10.5.2 (fixed in 10.5.2); from 10.6.0, before 10.6.2 (fixed in 10.6.2); version 10.7.0 only

Published 2026-06-09. Last modified 2026-10-07.