CRITICAL ROOT
Ivanti Sentry, formerly known as MobileIron Sentry, is an inline gateway that manages, encrypts, and secures traffic between mobile devices and back-end enterprise systems. It typically sits between corporate mobile fleets and resources such as Microsoft Exchange, controlling ActiveSync email traffic and application data, working alongside Ivanti Endpoint Manager Mobile (EPMM) to enforce device-level access controls.
Given Ivanti Sentry's role as a security gateway for enterprise mobile traffic, compromise of a Sentry appliance could have cascading consequences for connected backend systems and managed mobile devices.
More specifically, successful exploitation of CVE-2026-10520 can lead to full appliance compromise, data exfiltration, lateral movement, and persistent access, whereas successfully exploiting CVE-2026-10523 allows attackers to gain full administrative access to the security solution, which typically serves as a central point for network security monitoring and control. This level of access enables threat actors to modify security policies, disable monitoring capabilities, create backdoor accounts, and potentially pivot to other systems within the network.
CVE-2026-10520 is an OS command injection vulnerability with a maximum CVSS score of 10.0 that can be exploited remotely without authentication to execute arbitrary code with root privileges.
CVE-2026-10523 is an authentication bypass vulnerability (CVSS:3.1 9.9) that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access. The flaw enables attackers to circumvent normal authentication mechanisms, fundamentally undermining the security model of the system.
Patch The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.
Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via .
While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.
WatchTowr - NVD - NVD - VULDB - Bleeping Computer -
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
