If exploited, two critical vulnerabilities could allow for unauthenticated OS command injection or authentication bypass
If exploited, two critical vulnerabilities could allow for unauthenticated OS command injection or authentication bypass
The following platforms are known to be affected:
Ivanti Sentry (formerly MobileIron Sentry)
Proof-of-concept exploit for CVE-2026-10520
Security researchers have released a proof-of-concept technical writeup for vulnerability CVE-2026-10520.
The NHS England National CSOC assesses exploitation as highly likely.
Ivanti has released a security advisory to address two critical vulnerabilities in Ivanti Sentry. Successful exploitation could allow unauthenticated attackers to gain full administrative control or execute commands with root privileges on affected systems.
Affected organisations are encouraged to review Ivanti Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) and apply the relevant updates as soon as possible.
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Last edited: 10 June 2026 10:05 am
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
