Back Feeds.4Sysops Ivanti releases urgent patches for critical Sentry and EPMM vulnerabilities
Ivanti has issued emergency updates for its Sentry mobile gateway and Endpoint Manager Mobile (EPMM) platforms to address several critical security flaws. The most severe issue, CVE-2026-10520, is an OS command injection vulnerability with a maximum CVSS score of 10.0. This flaw allows remote, unauthenticated attackers to execute arbitrary code with root privileges by sending specially crafted messages to an exposed API. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
