Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3044 articles · 162748 vulns · 38/41 feeds (7d)
← Back to list
10.0
CVE-2026-10520EXPLOITEDPATCHED
ivanti · standalone_sentry

CVE-2026-10520: An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote

Description

This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. It is important for customers to know that exploitation of CVE-2026-10520 requires access to the management port (8443). Management interfaces should never be exposed to the internet, though honeypots often have misconfigurations to identify malicious behavior. The risk it poses is significantly decreased based on deployment and configuration.

Affected Products

VendorProductVersions
ivantistandalone_sentry10.5.1, 10.6.1, 10.7.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ivantisentrycert_advisory90%

References

  • https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-10520.yaml(exploit, nuclei)

Related News (12 articles)

Tier D
SecurityWeek1d ago
Ivanti Sentry Exploitation Attempts Hitting Honeypots
→ No new info (linked only)
Tier D
Heise Security1d ago
Ivanti Sentry: Verwirrung um Status von kritischem Befehlsschmuggel-Leck
→ No new info (linked only)
Tier E
Hacker News1d ago
Ivanti Sentry pre-auth RCE (CVE-2026-10520) – CVSS 10.0, public PoC, CISA KEV
→ No new info (linked only)
Tier D
CSO Online2d ago
Ivanti patches critical Sentry flaws that lead to full device takeover
→ No new info (linked only)
Tier D
Help Net Security3d ago
Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)
→ No new info (linked only)
Tier C
Rapid7 Blog3d ago
CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
→ No new info (linked only)
Tier D
BleepingComputer3d ago
Ivanti: Max severity Sentry flaw allows code execution as root
→ No new info (linked only)
Tier B
BSI Advisories3d ago
[NEU] [hoch] Ivanti Sentry: Mehrere Schwachstellen
→ No new info (linked only)
Tier E
Reddit r/cybersecurity3d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
→ No new info (linked only)
Tier E
Reddit r/netsec3d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-10520 | Ivanti Sentry up to R10.5.1/R10.6.1/R10.7.0 os command injection
→ No new info (linked only)
Tier B
CCCS Canada3d ago
Ivanti security advisory (AV26-567)
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.7.1
CWECWE-78
PublishedJun 9, 2026
Last enriched1d agov10
Tags
remote code executionstate-sponsored cyberespionageKnown Exploited VulnerabilitiesCISA
Trending Score101🔥
Source articles12
Independent12
Info Completeness11/14
Missing: epss, kev, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-6973EXPKEV
CVE-2026-6973: An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
Trending: 98
CRITICALCVE-2026-10523EXP
CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow
Trending: 71
HIGHCVE-2026-10727EXP
CVE-2026-10727: An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut
Trending: 40
HIGHCVE-2026-9614EXP
CVE-2026-9614: An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate
Trending: 13
CRITICALCVE-2026-8043
CVE-2026-8043: External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: affectedVersions
Jun 9, 2026
Updated: activelyExploited
Jun 10, 2026
Updated: affectedVersions
Jun 10, 2026
Updated: affectedVersions, patchAvailable, description, iocs
Jun 10, 2026
Updated: description, patchAvailable
Jun 10, 2026
Updated: tags
Jun 10, 2026
Updated: description, tags
Jun 10, 2026
Actively Exploited
Jun 12, 2026
Exploit Available
Jun 12, 2026
Patch Available
Jun 12, 2026
Updated: affectedVersions
Jun 12, 2026
Updated: description, tags
Jun 12, 2026

Version History

v10
Last enriched 1d ago
v10Tier D1d ago

Updated description with detailed exploitation conditions and added new tags related to CISA's KEV catalog.

descriptiontags
via SecurityWeek
v9Tier D1d ago

Added affected versions 10.5.1, 10.6.1, and 10.7.0, and updated patch available to 10.5.2.

affectedVersions
via Heise Security
v8Tier D2d ago

Added detailed description of Ivanti Sentry's functionality and included new tag related to state-sponsored cyberespionage.

descriptiontags
via CSO Online
v7Tier D3d ago

Updated 'activelyExploited' to false, set 'patchAvailable' to null, and added new tag 'remote code execution'.

tags
via Help Net Security
v6Tier C3d ago

Added a detailed description including an example HTTP request and updated affected versions and patch availability.

descriptionpatchAvailable
via Rapid7 Blog
v5Tier C3d ago

Updated affected versions to include 10.7.0, 10.6.1, and 10.5.1, added new patch versions, provided a detailed technical description, and included a new IOC for the vulnerable endpoint.

affectedVersionspatchAvailabledescriptioniocs
via Rapid7 Blog
v4Tier D3d ago

Updated description with additional context about Ivanti Sentry and confirmed patched versions.

affectedVersions
via BleepingComputer
v3Tier B3d ago

Updated actively exploited status to true based on new article information.

activelyExploited
via BSI Advisories
v2Tier C3d ago

Updated affected versions to R10.5.1, R10.6.1, R10.7.0 and corrected exploit availability to false.

affectedVersions
via VulDB
v13d ago

Initial creation