LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 11, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 14, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog on Jun 11, 2026, with a federal patch deadline of Jun 14, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This…

Ivanti Sentry contains an OS command injection vulnerability that can allow a remote unauthenticated attacker to achieve root-level remote code execution on the appliance. The issue is exploitable when the Sentry instance is in an unmanaged state and its endpoints are reachable from the internet.

How it works

The weakness is classified as CWE-78, OS command injection. An attacker supplies crafted input that is passed to an operating-system command without proper sanitization or parameterization. When successful, the injected commands execute with the privileges of the process, which in this case can reach root level. Exploitation requires the appliance to be unmanaged and its management interfaces externally reachable; configurations that enforce mTLS with EPMM or restrict HTTPS access through Neurons for MDM prevent external actors from reaching those interfaces.

Am I affected? How to find it in your systems

Inventory all Ivanti Sentry appliances, including any still labeled MobileIron Sentry. Confirm whether each instance is in a managed state and whether its endpoints are exposed to the internet. Review network diagrams and firewall rules to identify any externally reachable management interfaces. Check configuration for the presence of mTLS with EPMM or restricted HTTPS access via Neurons for MDM. No specific log signatures are provided in the available information; monitor for unexpected administrative sessions or command execution on the appliance itself and confirm details against the vendor advisory.

How to remediate

Apply mitigations in accordance with vendor instructions. Confirm the exact update or configuration change against the vendor advisory, as no version or patch identifiers are supplied here. After applying the update, verify that the appliance is placed under management and that external access to management interfaces is restricted through mTLS or equivalent controls.

If you can't patch immediately

Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Segment the appliance so that management interfaces are not reachable from untrusted networks. Enforce mTLS with EPMM or restrict HTTPS access through Neurons for MDM to render the vulnerable interfaces inaccessible to external actors. Increase monitoring of authentication attempts and administrative activity on the appliance until the update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this class have led to breaches in other products. Stakeholders are responsible for evaluating each asset’s internet exposure. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Sentry
WeaknessCWE-78
Added to CISA KEVJun 11, 2026
Federal patch deadlineJun 14, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities