INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Ivanti Sentry Gateways Exploited by CVE-2026-10520
| 2026-06-11 17:57 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is increasingly complex, with multiple vulnerabilities exploited by attackers targeting Ivanti Sentry gateways. The critical CVE-2026-10520 flaw in these secure gateway appliances allows remote code execution with root privileges, compromising internet-exposed gateways shortly after patches were released. This has already led to the discovery of backdoored (i.e., compromised) instances and exploitation attempts by researchers at Shadowserver. Ivanti Sentry acts as a critical component within enterprise environments, providing a gateway between mobile devices and internal corporate systems. As CISA continues to add multiple actively exploited vulnerabilities to its KEV catalog, including CVE-2026-1340 affecting Endpoint Manager Mobile and CVE-2026-1603 affecting Endpoint Manager, the risk of exploitation remains high.
Technical Mitigations AI-generated
• Implement a patch or update to Ivanti Sentry Gateways as soon as possible, ideally within the timeframe of shortly after patches were released.
• Monitor gateways for signs of exploitation and take immediate action if any are found.
• Ensure all users have up-to-date security updates and patches installed on their devices connected to Ivanti Sentry Gateways.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-10520CVE-2026-10520
CVE-2026-1340CVE-2026-1340
CVE-2026-1603CVE-2026-1603
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
January 2026
Threat actors exploited the Ivanti Sentry vulnerability CVE-2026-1340 in Gateways to target Endpoint Manager Mobile.
Click on any entity below to view its context and source!
infrastructure
Ivanti
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
vulnerability
CVE-2026-1340
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
vulnerability
CVE-2026-1603
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
attribution
CISA
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
attribution
KEV
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
attribution
Endpoint
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
2026/06/11
Threat actors used a publicly disclosed vulnerability exploit in Ivanti Sentry gateways to target the affected software.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-10520
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
infrastructure
Ivanti
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
organisation
Ivanti Sentry CVE-2026-10520
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
organisation
PoC
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
2026/06/11
Threat actors exploited a maximum-severity OS command injection flaw in Ivanti Sentry, allowing remote code execution with root privileges.
Click on any entity below to view its context and source!
organisation
CVE-2026-10520
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release.
infrastructure
Ivanti
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release.
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released.
Threat actors have started exploiting a maximum-severity OS command injection flaw in Ivanti Sentry, tracked as CVE-2026-10520, that allows remote code execution with root privileges.
Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
Ivanti Sentry flaw, tracked as
CVE-2026-10520
(CVSS score of 10.0), to its
Known Exploited Vulnerabilities (KEV) catalog
.
Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
Ivanti Sentry is a secure gateway appliance that sits between an organization’s internal systems and mobile devices, helping companies manage and protect mobile access to corporate resources.
Although Ivanti initially reported no evidence of active attacks, researchers at Shadowserver found that many internet-exposed Sentry gateways had already been backdoored shortly after the security updates were released.
However, attackers frequently target Ivanti flaws because they can provide direct access into enterprise networks and enable data theft.
Threat actors can specifically target Ivanti Sentry instances mainly because they sit in a very sensitive and powerful position inside enterprise environments.
Ivanti Sentry acts as a gateway between mobile devices and internal corporate systems.
Threat actors have
started exploiting
the maximum-severity OS command injection flaw in Ivanti Sentry, that allows remote code execution with root privileges.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
organisation
Ivanti Sentry Gateways Compromised Shortly
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release.
organisation
Patch Release
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released.
organisation
Ivanti Sentry
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released.
Ivanti Sentry is a secure gateway appliance that sits between an organization’s internal systems and mobile devices, helping companies manage and protect mobile access to corporate resources.
organisation
IP
Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild.
Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild.
infrastructure
5.2
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
infrastructure
6.2
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
infrastructure
7.1
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
organisation
An OS Command Injection
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
organisation
Shadowserver
Although Ivanti initially reported no evidence of active attacks, researchers at Shadowserver found that many internet-exposed Sentry gateways had already been backdoored shortly after the security updates were released.
2026/06/12
Threat actors used Ivanti Sentry's CVE-2026-10520 vulnerability exploit to target Gateways.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-10520
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
infrastructure
Ivanti
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
organisation
Ivanti Sentry CVE-2026-10520
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
organisation
PoC
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
June 14, 2026
Threat actors exploited the Ivanti Sentry vulnerability in gateways to gain unauthorized access.
June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges Ivanti Sentry users to patch vulnerabilities by June 14 due to a known exploited flaw in the software.
Click on any entity below to view its context and source!
infrastructure
Ivanti
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14.
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog.
attribution
Ivanti Sentry
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14.
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14.
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog.
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14.
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog.
Tactical Metrics
Metrics
infrastructure
Ivanti
Affected Product
Click for context!
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release.
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release
Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were rele…
Threat actors have started exploiting a maximum-severity OS command injection flaw in Ivanti Sentry, tracked as CVE-2026-10520, that allows remote code execution with root privileges.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
Ivanti Sentry is a secure gateway appliance that sits between an organization’s internal systems and mobile devices, helping companies manage and protect mobile access to corporate resources.
Although Ivanti initially reported no evidence of active attacks, researchers at Shadowserver found that many internet-exposed Sentry gateways had already been backdoored shortly after the security updates were released.
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today.
Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild.
However, attackers frequently target Ivanti flaws because they can provide direct access into enterprise networks and enable data theft.
Threat actors can specifically target Ivanti Sentry instances mainly because they sit in a very sensitive and powerful position inside enterprise environments.
Ivanti Sentry acts as a gateway between mobile devices and internal corporate systems.
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including
CVE-2026-1340
affecting Endpoint Manager Mobile and
CVE-2026-1603
affecting Endpoint Manager, both enabling attackers to bypass…
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14.
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catal…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
Ivanti Sentry flaw, tracked as
CVE-2026-10520
(CVSS score of 10.0), to its
Known Exploited Vulnerabilities (KEV) catalog
.
Threat actors have
started exploiting
the maximum-severity OS command injection flaw in Ivanti Sentry, that allows remote code execution with root privileges.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild.
Metrics
infrastructure
5.2
Software Version
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
Metrics
infrastructure
6.2
Software Version
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
Metrics
infrastructure
7.1
Software Version
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ”
reads the advisory
.
Intelligence Sources
Security Affairs
2026-06-11
Security Affairs
2026-06-12
Security Affairs
2026-06-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
10x
organisation
Identified Entity
CVE-2026-10520
entity
9x
attribution
Attributing Entity
CISA
authority
6x
timeline
Temporal Reference
2026/06/11
date
3x
vulnerability
Exploited CVE
CVE-2026-10520
cve
3x
infrastructure
Software Version
5.2
version
Contextual Telemetry
Context Block
6 METRICS
infrastructure
Affected Product
Ivanti
software
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Vulnerable Instances
19
vulnerable instances
general metric
Scans
2
scans
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
vulnerability
CVSS Score
10
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.