Ivanti Sentry Pre-Auth Root RCE – CVE-2026-10520
TL;DR: A maximum-severity flaw (CVSS 10.0) in Ivanti Sentry lets an unauthenticated attacker reachable over the network run commands as root on the appliance. It is in CISA’s Known Exploited Vulnerabilities catalogue and was being attacked within days of the patch. If you run Sentry, upgrade to 10.5.2, 10.6.2 or 10.7.1 immediately.
Key takeaways
- CVE-2026-10520 is an unauthenticated OS command injection in the Ivanti Sentry MICS administrative API, scoring a perfect 10.0 on CVSS v3.1.
- A successful attack gives root-level remote code execution — full control of the gateway that sits between mobile devices and corporate email and apps.
- CISA added it to the KEV catalogue on 11 June 2026 and set an unusually tight federal patch deadline of 14 June 2026 (a three-day window).
- Exploitation began shortly after a public technical write-up and detection script appeared, so treat any internet-exposed, unpatched Sentry as compromised until proven otherwise.
- Fixed in Sentry 10.5.2, 10.6.2 and 10.7.1. There is no full mitigation short of patching — restrict access to the admin interface and hunt for compromise.
| CVSS Score | 10.0 (CVSS v3.1) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Vulnerability Type | OS Command Injection → unauthenticated root RCE (CWE-78) |
| Affected Products | Ivanti Sentry 10.5.1, 10.6.1, 10.7.0 and earlier |
| Attack Vector | Network — no authentication, no user interaction required |
| Actively Exploited | Yes (CISA KEV, added 11 Jun 2026; public PoC / detection script available) |
| Patch Available | Yes — fixed in 10.5.2, 10.6.2 and 10.7.1 |
| Disclosure Date | 9 June 2026 (Ivanti advisory & patches) |

What is CVE-2026-10520?
CVE-2026-10520 is a critical OS command injection vulnerability in Ivanti Sentry, the security gateway formerly known as MobileIron Sentry. Sentry acts as a gatekeeper between mobile devices outside the corporate perimeter and internal systems such as Exchange and ActiveSync, so it is routinely reachable from the internet. The flaw lets a remote attacker with no credentials send a crafted request to Sentry’s management API and have the appliance execute arbitrary operating-system commands as root. Ivanti disclosed it alongside an authentication-bypass bug, CVE-2026-10523, on 9 June 2026, and it has since been confirmed under active exploitation. With a CVSS v3.1 base score of 10.0, it sits at the absolute top of the severity scale.
How the Ivanti Sentry exploit works
In plain terms: Sentry exposes an internal administrative API — the MICS (MobileIron Configuration Service) interface — that was only ever meant to take configuration commands from trusted, internal callers. Because of a missing authentication check, that API will accept a request from anyone who can reach it over the network. One of the parameters it processes is passed into a system command without proper sanitisation, so an attacker can append their own shell command and have it run with root privileges.
In more depth, the root cause is a classic command-injection pattern (CWE-78): user-controlled input flows into an OS command interpreter without being neutralised. The pre-conditions are minimal — network reachability to the Sentry management interface and an unpatched build. No valid session, password or user interaction is needed, which is why the CVSS vector is AV:N/AC:L/PR:N/UI:N with a scope change (S:C) and high confidentiality, integrity and availability impact. Once code runs as root, the attacker can read configuration and secrets, harvest credentials and session tokens, impersonate legitimate users, deploy a persistent web shell, and pivot toward the internal mail and application servers that Sentry fronts.

The following is a non-operational, illustrative sketch of the shape of such a request — deliberately incomplete and not a working exploit:
POST /mics/services/<config-endpoint> HTTP/1.1Host: sentry.example.comContent-Type: application/x-www-form-urlencodedparam=value; <attacker-supplied-shell-command>
The key idea is that the trailing shell metacharacters break out of the intended command context. We are not publishing payloads, exact endpoints or parameter names; defenders who need that detail should consult the vendor advisory and the WatchTowr research linked below.
Is CVE-2026-10520 actively exploited?
Yes. Ivanti’s initial advisory on 9 June noted no known exploitation, but the situation changed within days. Security researchers at WatchTowr published a technical comparison of vulnerable and patched builds plus a detection script, and opportunistic exploitation followed quickly. On 11 June 2026 CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities (KEV) catalogue, citing evidence of attempted exploitation — Ivanti told reporters the addition was based on reports of exploitation attempts against honeypots. CISA set a federal remediation deadline of 14 June 2026, an unusually short three-day window that underlines how seriously the agency rates the risk. A public proof-of-concept / vulnerability-check script is available, lowering the bar for less sophisticated attackers. No specific named threat actor or APT group has been publicly attributed at the time of writing.

How to fix CVE-2026-10520: remediation & mitigation
Patch: Upgrade Ivanti Sentry to a fixed build — 10.5.2, 10.6.2 or 10.7.1 — depending on your branch. This is the only complete fix. Given confirmed in-the-wild exploitation, treat patching as an emergency change.
If you can’t patch immediately:
- Restrict network access to the Sentry management/MICS interface so it is not reachable from the internet or untrusted networks — limit it to a tightly controlled management segment.
- Place the appliance behind a WAF or upstream filtering and block anomalous requests to the administrative API paths.
- Use WatchTowr’s published check script (or equivalent) to confirm whether your instances are vulnerable, and prioritise any that are internet-facing.
After patching: Assume any exposed, unpatched appliance may already be compromised. Rotate all credentials and secrets stored on or accessible from Sentry, invalidate active sessions and tokens, and review configuration for unauthorised changes (including the related auth-bypass bug CVE-2026-10523, which allows rogue admin account creation). Rebuild from a known-good image if compromise is suspected.
Detection / IOCs: Hunt for unexpected processes spawned by the Sentry web/service account, new or modified files and web shells in web-accessible directories, anomalous outbound connections from the appliance, and unfamiliar admin accounts. Inspect MICS/management-API access logs for unauthenticated requests from external addresses. Cross-reference vendor- and researcher-published indicators as they become available.
Frequently asked questions
How serious is CVE-2026-10520?
About as serious as it gets. It scores a perfect 10.0, requires no authentication and yields root code execution on a device that typically faces the internet and bridges to internal mail and app servers.
Is my organisation affected?
If you run Ivanti Sentry 10.5.1, 10.6.1, 10.7.0 or any earlier build, yes. Internet-exposed instances are at highest risk and should be patched first.
Has it been exploited in the wild?
Yes — CISA added it to the KEV catalogue on 11 June 2026 based on evidence of exploitation attempts, and a public detection script and technical analysis exist. Exploitation ramped up after the patch and write-up were released.
What should I do right now?
Upgrade to 10.5.2, 10.6.2 or 10.7.1 immediately. If you cannot patch this hour, lock down access to the management interface, then assume-breach: rotate secrets, kill sessions and hunt for indicators of compromise.
Sources & further reading
- Ivanti Security Advisory — Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)
- CISA Known Exploited Vulnerabilities Catalog
- Help Net Security — Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)
- Rapid7 — CVE-2026-10520, CVE-2026-10523: Multiple critical vulnerabilities affecting Ivanti Sentry
- WatchTowr Labs — Ivanti Sentry pre-auth OS command injection research
- BleepingComputer — CISA gives feds 3 days to patch Ivanti flaw exploited in attacks
- Security Affairs — CVE-2026-10520 exploited: Ivanti Sentry gateways compromised shortly after patch release
ZeroDayHub tracks critical vulnerabilities as they break. Subscribe for updates.





Leave a Reply