A critical Ivanti Sentry vulnerability, CVE-2026-10520, is being actively exploited to achieve unauthenticated remote code execution with root privileges through OS command injection. The flaw stems from improper handling of internal configuration commands exposed through an externally accessible API, allowing full compromise of affected appliances. CISA added the bug to its Known Exploited Vulnerabilities catalog, and FortiGuard reported 886 blocked exploitation attempts in 24 hours and 8,406 over seven days, with activity rising 82% week over week across the technology, automotive, banking/finance/insurance, and education sectors.
The vulnerability affects Ivanti Sentry versions before 10.5.2, 10.6.2, and 10.7.1, and Ivanti has released those versions as fixes. Because Sentry operates as an inline gateway between mobile devices and enterprise back-end systems, successful exploitation can expose a critical network chokepoint and enable broad downstream access. Ivanti also addressed CVE-2026-10523 in the same update, though it was not reported as exploited, and defenders are being urged to upgrade immediately and restrict management and service interfaces from untrusted networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
FortiGuard said it blocked 886 exploitation attempts in the prior 24 hours and 8,406 in the prior 7 days for CVE-2026-10520, with weekly activity up 82%. It also noted targeting across the technology, automotive, banking/finance/insurance, and education sectors.
CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog after active exploitation was observed. This formally marked the Ivanti Sentry flaw as exploited in the wild.
Ivanti released patched Ivanti Sentry versions 10.5.2, 10.6.2, and 10.7.1 to address the critical OS command injection flaw CVE-2026-10520; the same update also included CVE-2026-10523. The vulnerability affects earlier Sentry versions and can allow unauthenticated root-level command execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.