Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ivanti Sentry OS command injection RCE as root (CVE-2026-10520)

Vulnerability
First reported
Last updated
Happening score
H score 48
3 unique sources, 5 articles

Summary

Hide ▲

Ivanti Sentry has a critical OS command injection vulnerability, CVE-2026-10520, that can let remote attackers execute code with root privileges on the gateway appliance. Ivanti said it had no evidence of exploitation in the wild at disclosure. The company released fixed builds R10.5.2, R10.6.2, and R10.7.1 to address the flaw. Administrators should upgrade affected gateways to reduce exposure.

Related Happenings

CISA orders FCEB Ivanti Sentry remediation under BOD 26-04

Public Sector Action
H score36 First: 12.06.2026 11:26 Last: 12.06.2026 11:26 Sources 1

How related: On Thursday, CISA added the bug to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to address it within three days, in line with BOD 26-04 guidance to prioritize patching based on risk.

About this happening: CISA ordered FCEB agencies to secure Ivanti Sentry within three days after confirming CVE-2026-10520 is being actively exploited, creating immediate remedi...

CISA emergency patch deadline for Ivanti EPMM

Public Sector Action
H score40 First: 08.05.2026 15:16 Last: 08.05.2026 15:16 Sources 1

About this happening: CISA ordered U.S. federal agencies to patch Ivanti EPMM by midnight Sunday, May 10 after adding CVE-2026-6973 to its list of vulnerabilities exploited in attacks....

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

Timeline

  1. 10.06.2026 09:26 6 articles · 1mo ago

    Ivanti releases Sentry patches for CVE-2026-10520 and CVE-2026-10523

    Mitigation Patch Update

    Ivanti released Sentry versions R10.5.2, R10.6.2, and R10.7.1 to fix CVE-2026-10520, an OS command injection flaw that can let remote attackers execute code as root, and CVE-2026-10523, a critical authentication bypass that can allow unauthenticated attackers to create rogue administrative accounts and gain full administrative access. Ivanti said it had no evidence of exploitation in the wild at disclosure and advised administrators to upgrade affected systems.

    Show sources