Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Ivanti Sentry CVE-2026-10520 exploit hits gateways within 24 hours of patch release
    Technology

    Ivanti Sentry CVE-2026-10520 exploit hits gateways within 24 hours of patch release

    Gary BehanBy Gary Behan14/08/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Ivanti Sentry CVE-2026-10520 exploit
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    Federal agencies in the United States have been ordered to patch the Ivanti Sentry CVE-2026-10520 exploit within three days, after the internet security watchdog Shadowserver reported that attackers had already backdoored exposed Sentry gateways less than 24 hours after Ivanti issued a fix. The flaw carries a maximum severity rating and stems from an OS command injection weakness in Ivanti’s Sentry security gateway appliance, formerly known as MobileIron Sentry.

    Ivanti released patches on Tuesday, stating at the time that it had no evidence of in-the-wild exploitation. By Wednesday, Shadowserver had already observed active attacks. According to Dark Reading, the vulnerability affects Ivanti Sentry versions prior to R10.5.2, R10.6.2 and R10.7.1. Ivanti‘s own advisory notes that exploitation requires access to the management port (8443), which means organisations that have not restricted external access to that port are at heightened risk.

    Shadowserver warns unpatched systems are likely already compromised

    Shadowserver currently tracks just over 50 Sentry admin portals exposed online, though it has been clear that this figure almost certainly understates the true picture. Many Ivanti Sentry instances are unreachable by its scanner, possibly because organisations have blocklisted it, meaning the real number of exposed or compromised systems could be considerably higher.

    ‘We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today,’ Shadowserver said. ‘While our detection is on the lowish side due to multiple Ivanti Sentry instances not reachable in our scans (blocklisted?), if you have not patched now you are most likely compromised.’

    Ivanti has not yet updated its advisory to reflect active exploitation, and a spokesperson did not respond to requests for comment from BleepingComputer regarding the ongoing attacks.

    CISA adds CVE-2026-10520 to KEV catalogue under new directive BOD 26-04

    On Thursday, CISA confirmed active exploitation and added CVE-2026-10520 to its Known Exploited Vulnerabilities (KEV) catalogue, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their Sentry instances within three days under Binding Operational Directive (BOD) 26-04. This directive was itself issued only on Wednesday, superseding the older BOD 19-02 and BOD 22-01.

    BOD 26-04 sets out a hierarchy of patching priorities for federal agencies: assets that are publicly exposed online, flaws added to the KEV catalogue, vulnerabilities that can be exploited at scale in automated attacks, and weaknesses that give attackers partial or total control of a targeted system. CVE-2026-10520 meets every one of those criteria. ‘This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,’ CISA warned.

    The directive also instructs agencies to follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. CVE-2026-10520 is the first vulnerability for which BOD 26-04 formally applies, though CISA has issued similar three-day patch orders in recent weeks for a Check Point VPN zero-day, a high-severity Oracle WebLogic Server vulnerability, and an actively exploited cPanel plugin flaw.

    Patched versions available, with watchTowr Labs releasing a detection script

    Organisations running Ivanti Sentry should upgrade immediately to the patched releases: versions 10.5.2, 10.6.2, and 10.7.1, according to eSentire. eSentire also notes that watchTowr Labs has published a detailed technical write-up on the vulnerability alongside a publicly available detection script, which defenders can use to check whether their environments have already been compromised. Given that the public proof-of-concept is already driving active exploitation attempts, that script may be worth running before the patch is even applied.

    The broader Ivanti track record adds context here. CISA has flagged 35 vulnerabilities across Ivanti products that have been abused in attacks over the past several years, with 12 of those targeted by ransomware gangs. The Sentry gateway line has been a recurring target; admins who have not yet restricted port 8443 from external access should treat that as an immediate priority alongside applying the fix.

    CISA’s three-day deadline for FCEB agencies falls on Sunday.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleAudiA6 ransomware laundering service dismantled after $380m operation
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    AudiA6 ransomware laundering service dismantled after $380m operation

    13/08/2026

    Microsoft patches BitLocker recovery Windows Server 2025 flaw two months on

    13/08/2026

    Mythos Preview Offensive Security Test: A Brain in Search of a Body

    13/08/2026

    NFCShare Android Malware Spreads via Fake Banking App Updates on GitHub

    10/06/2026

    Oxford CareerConnect Data Breach Exposes User Credentials via GTI Platform Hack

    09/06/2026

    Best Face Swap Online Tools of 2026 (Tested and Compared)

    31/01/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.