CVE-2026-10520

Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability

Severity
critical
Actively exploited
actively exploited (KEV)
99.9 %
Critical — model predicts very high exploitation likelihood in the next 30 days.
Published
2026-06-09 16:16 UTC
CWE-78

Weakness classes (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 08:10 UTC· nvd@nist.gov
    • Translation: Title: Sentry de Ivanti, Description: Una vulnerabilidad de inyección de comandos del sistema operativo en Ivanti Sentry anterior a las versiones R10.5.2, R10.6.2 y R10.7.1 permite a un usuario remoto no autenticado lograr ejecución remota de código a nivel de root.
  2. Initial Analysis2026-06-12 12:42 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:* versions up to (excluding) 10.5.2 *cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:* versions from (including) 10.6.0 up to (excluding) 10.6.2 *cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
    • Reference Type: CISA-ADP: https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 Types: Third Party Advisory
    • Reference Type: ivanti: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US Types: Patch, Vendor Advisory
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 Types: US Government Resource

Description

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Source: CISA_KEV

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Linked advisories