Skip to content
CC-4795

CC-4795

Digital.Nhs.Uk [email protected] (NHS Digital) June 10, 2026

If exploited, two critical vulnerabilities could allow for unauthenticated OS command injection or authentication bypass

If exploited, two critical vulnerabilities could allow for unauthenticated OS command injection or authentication bypass

The following platforms are known to be affected:

Ivanti Sentry (formerly MobileIron Sentry)

Proof-of-concept exploit for CVE-2026-10520

Security researchers have released a proof-of-concept technical writeup for vulnerability CVE-2026-10520.

The NHS England National CSOC assesses exploitation as highly likely.

Ivanti has released a security advisory to address two critical vulnerabilities in Ivanti Sentry. Successful exploitation could allow unauthenticated attackers to gain full administrative control or execute commands with root privileges on affected systems.

Affected organisations are encouraged to review Ivanti Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) and apply the relevant updates as soon as possible.

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Last edited: 10 June 2026 10:05 am