CVE-2026-10520: Critical Ivanti Sentry Remote Code Execution Vulnerability
Ivanti Sentry contains a critical flaw that allows attackers to execute arbitrary system commands with root-level privileges without needing credentials or user interaction. An unauthenticated attacker on the network can exploit this remotely to gain complete control of affected systems. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on June 11, 2026, indicating active exploitation in the wild.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 10.0 CRITICAL · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-78
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-09 / 2026-06-17
- KEV due date
- 2026-06-14 (added 2026-06-11)
NVD description (verbatim)
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-10520 is an OS command injection vulnerability (CWE-78) in Ivanti Sentry that permits remote code execution at the root privilege level. The vulnerability exists in versions prior to R10.5.2, R10.6.2, and R10.7.1. The attack requires no authentication, has low attack complexity, and can be triggered remotely over the network without user interaction, resulting in a CVSS v3.1 score of 10.0 (CRITICAL). The attack impacts confidentiality, integrity, and availability across the entire system scope.
Business impact
Exploitation grants attackers root-level access to Ivanti Sentry deployments, enabling complete system compromise. This can lead to data exfiltration, system destruction, lateral movement to connected infrastructure, and operational disruption. Organizations relying on Sentry for access control or security management face total loss of control over those functions during active exploitation. The KEV designation confirms this is being actively exploited, elevating urgency beyond theoretical risk.
Affected systems
Ivanti Standalone Sentry installations running versions before R10.5.2 (for R10.5.x branch), R10.6.2 (for R10.6.x branch), and R10.7.1 (for R10.7.x branch) are vulnerable. Organizations should verify their installed version against these thresholds immediately. All versions prior to these patches within their respective release lines require patching.
Exploitability
This vulnerability is highly exploitable. It requires no authentication, no user interaction, and has minimal attack complexity. Network accessibility is straightforward for any attacker with baseline connectivity to the target. The KEV designation confirms active exploitation in real-world attacks as of June 11, 2026, with an initial remediation deadline of June 14, 2026, indicating rapid weaponization.
Remediation
Upgrade Ivanti Sentry to R10.5.2 or later (if on R10.5.x branch), R10.6.2 or later (if on R10.6.x branch), or R10.7.1 or later (if on R10.7.x branch). Organizations should prioritize patching within 24–48 hours given the CRITICAL severity and active exploitation status. Verify patch deployment against Ivanti's official advisory to confirm the exact version numbers for your release track.
Patch guidance
Consult Ivanti's official security advisory for R10.5.2, R10.6.2, and R10.7.1 patch releases. Download patches only from Ivanti's trusted distribution channels. Before deployment in production, test patches in a staging environment to confirm compatibility with your configuration. Given the CRITICAL nature and KEV status, expedited patching is justified even in change-controlled environments; coordinate with operations and security teams to deploy out-of-cycle if necessary. Document patch application dates and versions for compliance audit trails.
Detection guidance
Monitor network traffic for unusual connections to Ivanti Sentry ports and endpoints. Look for signs of command injection in logs—unusual shell commands, unexpected process spawning, or suspicious script execution originating from the Sentry service or its network interface. Search for evidence of post-exploitation activity: lateral movement attempts, new user accounts, privilege escalation, or data access outside normal baselines. Implement or review EDR/XDR coverage on systems hosting Sentry to detect runtime anomalies. If unpatched systems exist, isolate them from production networks pending patching.
Why prioritize this
CRITICAL severity combined with public KEV listing and active exploitation makes this the highest priority. The combination of zero authentication requirements, remote network accessibility, and root-level impact means every unpatched instance is an immediate, exploitable attack vector. The narrow remediation window (14 days from KEV publication) imposed by CISA underscores operational urgency.
Risk score, explained
The CVSS 3.1 score of 10.0 reflects maximum severity: network-accessible, unauthenticated, low-complexity exploitation leading to complete system compromise (confidentiality, integrity, and availability all HIGH, system scope CHANGED). The KEV status elevates practical risk beyond the numerical score—active exploitation confirms adversaries are weaponizing this flaw in real attacks, not just in labs.
Frequently asked questions
What is the difference between the three patched versions (R10.5.2, R10.6.2, R10.7.1)?
These represent patches across three separate release branches of Ivanti Sentry. Organizations running R10.5.x should upgrade to at least R10.5.2, those on R10.6.x to R10.6.2, and those on R10.7.x to R10.7.1 or later. Verify your current version first, then apply the appropriate patch for your branch.
If we patch today, are we protected from this vulnerability?
Yes, applying the appropriate patch version closes this specific command injection flaw. However, ensure you apply the correct patch for your release branch (R10.5.2, R10.6.2, or R10.7.1 or later). After patching, monitor for other CVEs and maintain a regular patching cadence to address future issues.
What does the KEV designation mean for our organization?
The CISA KEV catalog lists vulnerabilities with evidence of active, real-world exploitation. This means attackers are already using tools and techniques to target this flaw. Organizations running unpatched Sentry instances should assume they may be targeted and prioritize patching accordingly.
Do we need to assume our systems were compromised during exploitation?
If your unpatched Sentry instances were exposed to the internet or untrusted networks before patching, assume potential compromise. Conduct forensic analysis of logs and system activity for signs of unauthorized access, privilege escalation, or data exfiltration. Engage your security operations or incident response team if evidence of compromise is found.
This analysis is based on CVE-2026-10520 data published as of June 17, 2026. Verify all version numbers and patch details against Ivanti's official security advisories before deployment. SEC.co provides intelligence for informational purposes; organizations must conduct their own risk assessment and testing before applying patches. Patch deployment decisions should align with your organization's change management and business continuity policies. Source: NVD (public-domain), retrieved 2026-07-19. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2025-41265HIGHWaterfall WF-500 TX Host OS Command Injection (CVSS 7.2)
- CVE-2025-41266HIGHWaterfall WF-500 TX Host Command Injection Vulnerability Analysis
- CVE-2025-41267HIGHWaterfall WF-500 TX Host Command Injection Vulnerability
- CVE-2025-41279HIGHOS Command Injection in Waterfall WF-500 RX Host Administration WebUI
- CVE-2025-41281HIGHWaterfall WF-500 OS Command Injection
- CVE-2025-66273HIGHQNAP Command Injection in QTS and QuTS hero
- CVE-2025-66279HIGHQNAP NAS Command Injection – Admin Authentication Required, HIGH Severity
- CVE-2025-69755HIGHNeterbit NW-431F Router RCE and Data Exposure Vulnerability
Preview — this page is review (quality 0.929). high-value: hold for review.