Known vulnerability record

CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Stable IDcve:CVE-2026-10520Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

Keep the signals separate

CVSS severitycriticalScore 10 · source ivanti
EPSS probability99.9%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-06-11
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-06-09
CVE modified
2026-06-12
KEV date added
2026-06-11
Dataset fetched
2026-08-21T03:55:02.403Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.