Skip to main content
Mallory
Back to intelligence
perimeter-device-exposurewidely-deployed-product-advisoryembedded-device-vulnerabilityidentity-authentication-vulnerability

Critical Ivanti Sentry Flaws Enable Root RCE and Admin Account Creation

Updated 7h agoFirst seen Jun 9, 202624 sources

Ivanti disclosed two severe vulnerabilities in Ivanti Sentry that allow remote compromise of exposed appliances. CVE-2026-10520 is an OS command injection flaw (CWE-78) that can let an unauthenticated attacker achieve root-level remote code execution, while CVE-2026-10523 is an authentication bypass (CWE-288) that can be used to create arbitrary administrative accounts and obtain full administrative access. Both issues affect Ivanti Sentry versions earlier than R10.5.2, R10.6.2, and R10.7.1.

The vulnerabilities carry severe impact ratings, with CVE-2026-10520 described as critical and CVE-2026-10523 as high severity, reflecting risks to confidentiality, integrity, and availability. Ivanti said the flaws were addressed in R10.5.2, R10.6.2, and R10.7.1, and published a security advisory covering both CVEs, making patching of affected Sentry deployments an immediate priority.

Share:
Critical Ivanti Sentry Flaws Enable Root RCE and Admin Account Creation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jun 11, 20262d ago

CISA adds CVE-2026-10520 to KEV catalog

On 2026-06-11, CISA added Ivanti Sentry vulnerability CVE-2026-10520 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The notice directed Federal Civilian Executive Branch agencies to prioritize remediation under Binding Operational Directive 26-04 and assess whether systems were compromised before patching.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

Shadowserver reports active exploitation of CVE-2026-10520

Shadowserver reported that attackers were actively exploiting Ivanti Sentry flaw CVE-2026-10520 after a public proof-of-concept became available. It said exploitation attempts surged and that many exposed Sentry gateways were likely already backdoored or compromised.

Max severity Ivanti Sentry vulnerability now exploited in attacks

Ivanti advisory also covers two EPMM vulnerabilities

Ivanti's June 2026 advisory also described two Ivanti EPMM flaws, CVE-2026-6973 and CVE-2026-10727, involving Apache directive injection or command execution paths that require administrator authentication. The reference states CVE-2026-6973 was already listed in CISA KEV as actively exploited, while Ivanti said there was no known public exploitation of CVE-2026-10727 at disclosure.

Ivanti June 2026 - Vulnerability Advisory Deep Dive - TheCyberThrone
Jun 10, 20263d ago

watchTowr Labs publishes public PoC for Ivanti Sentry flaws

watchTowr Labs published technical analysis and a public proof-of-concept exploit for CVE-2026-10520 and CVE-2026-10523, lowering the barrier to exploitation of the Ivanti Sentry vulnerabilities. The report also noted Ivanti said it was not aware of customer exploitation at the time of disclosure.

Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10
Jun 9, 20264d ago

Ivanti publishes Sentry advisory and fixed versions

Ivanti published a security advisory covering CVE-2026-10520 and CVE-2026-10523 and stated that fixes are available in Ivanti Sentry versions R10.5.2, R10.6.2, and R10.7.1. The advisory confirms affected versions are those prior to these releases.

CVE-2026-10523 - Ivanti Sentry Authentication Bypass

Ivanti discloses CVE-2026-10523 authentication bypass in Sentry

On 2026-06-09, CVE-2026-10523 was disclosed as an authentication bypass in Ivanti Sentry affecting versions before R10.5.2, R10.6.2, and R10.7.1. A remote unauthenticated attacker could create arbitrary administrative accounts and gain full administrative access.

CVE-2026-10523 - Ivanti Sentry Authentication Bypass

Ivanti records CVE-2026-10520 for Sentry command injection

On 2026-06-09, CVE-2026-10520 was recorded as an OS command injection vulnerability in Ivanti Sentry affecting versions before R10.5.2, R10.6.2, and R10.7.1. The flaw allows a remote unauthenticated attacker to achieve root-level remote code execution.

CVE-2026-10520 - Ivanti Sentry OS Command Injection
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

44 LINKEDOpen in app
Affected products
11 linked
CpanelExtensible Operating SystemInsightvmCheck Point VpnNexposeCatalyst SD-WAN ManagerSentryEdgeOperaChromeOracle Weblogic Server
Organizations
22 linked
IvantiWatchTowrTruesecBleepingComputerShadowServer FoundationCisco SystemsRapid7Picus SecurityArista NetworksMicrosoft CorporationGitHubGoogleCheck Point Software TechnologiesSOCRadarDefusedInternational Business MachinesDark ReadingSolarWindsFortinetCpanelOracleSecurity Affairs
Breaches
1 linked
DUTCHDATAPROTECTIONAUTHORITY-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Ivanti Sentry Flaws Enable Root RCE and Admin Account Creation | Mallory