Critical Known exploited (KEV) CVE-2026-10520

OS command injection in Ivanti Sentry (CVE-2026-10520) — unauthenticated root-level remote control

Ivanti Sentry Added to KEV Jun 11, 2026 Federal remediation due 2026-06-14

Ivanti Sentry (formerly MobileIron Sentry), a mobile-device management gateway, contains an OS command injection flaw that lets a remote, unauthenticated attacker execute code as root. CISA listed it as known-exploited (KEV) (CVSS 10.0 Critical, per NVD).

Key facts

  • CVE IDCVE-2026-10520
  • CVSS base score10 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Affected (vendor / product)Ivanti Sentry
  • CWECWE-78
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-06-14 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • OS command injection (CWE-78) in Ivanti Sentry (formerly MobileIron Sentry; a mobile-management gateway)
  • In an unmanaged state, a remote, unauthenticated attacker can execute code as root
  • Listed in CISA KEV = exploitation confirmed; NVD base score is the maximum 10.0 Critical
  • Response: apply Ivanti's official fixes/mitigations and review external exposure and access logs
  • Federal civilian remediation deadline was June 14, 2026 (a practical benchmark for others)
  • In an unmanaged state neither configuration nor updates arrive, and unauthenticated root execution can succeed.

1Ivanti Sentry as management infrastructure

CVE-2026-10520 is an OS command injection vulnerability (CWE-78) in Ivanti Sentry (formerly MobileIron Sentry). Sentry is a gateway product that sits between mobile devices (smartphones, etc.) and internal mail/app systems, relaying traffic and handling authentication.

2The unmanaged state

Per public information, when the Sentry appliance is in an unmanaged state, a remote, unauthenticated attacker can achieve root-level remote code execution (RCE). OS command injection is a flaw where input that should be treated as data is instead interpreted and executed as an OS command inside the device; when it succeeds, the device itself can be taken over.

3Why edge devices are dangerous

This class of device is dangerous because (1) it sits at the boundary between the internet and the internal network and is reachable from outside, and (2) as the linchpin connecting mobile devices and internal systems, its compromise becomes a foothold for internal intrusion. The flaw needs no authentication and has low complexity, with impact extending beyond the device itself.

4Being unmanaged is the condition

The condition given for this vulnerability is that the Sentry appliance is in an unmanaged state. Whether it is managed is itself the line between safe and not.

ManagedUnmanaged
Configuration and updates arrive centrallyNeither configuration nor updates arrive
Its operating state is knownIt may have fallen off the asset register
A vulnerability found can be remediatedUnauthenticated root execution can succeed

Sentry is a gateway product standing between mobile devices such as smartphones and internal mail and application platforms, relaying traffic and handling authentication. It sits at the boundary, reachable from outside, and a breach makes it a foothold into the internal network. Alongside applying the fix, checking the device's managed state and its external exposure is the point of the response.

Why it matters

Any organization running mobile-device management via a boundary gateway can be affected. Unauthenticated root RCE leads directly to initial intrusion, so asset inventory (which Sentry units are exposed), prompt patching, and log review are the priorities. It reflects the continued targeting of perimeter appliances.

FAQ

What is Ivanti Sentry?
A management gateway (formerly MobileIron Sentry) that sits between mobile devices and internal mail/app systems, relaying traffic and handling authentication. It is placed at the network boundary.
What is OS command injection?
A flaw where input meant to be treated as text is executed as an OS command inside the device. When it succeeds the device can be taken over — here, with the highest (root) privilege.
What should I do?
Check Ivanti's official advisory for affected versions and apply fixes/mitigations. Because it is an internet-facing perimeter device, act as early as possible and review access logs.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Ivanti#Mobile management#Command injection#Perimeter defense#RCE
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.