Maximum-Severity Ivanti Sentry Vulnerability Now Exploited in Active Attacks

Maximum-Severity Ivanti Sentry Vulnerability Now Exploited in Active Attacks

Share Facebook X LinkedIn Email

Attackers are actively exploiting a maximum-severity Ivanti Sentry vulnerability that allows root-level command execution on exposed secure mobile gateways, prompting warnings that unpatched internet-facing systems should be treated as potentially compromised.

Attackers are actively exploiting a recently patched maximum-severity vulnerability in Ivanti Sentry, targeting internet-exposed secure mobile gateways to execute commands with root-level privileges.

The vulnerability, tracked as CVE-2026-10520, is an operating system command injection flaw affecting Ivanti Sentry, formerly known as MobileIron Sentry. The appliance is used to secure traffic between remote mobile devices and back-end corporate systems, making it a sensitive gateway into enterprise environments.

Ivanti patched the flaw on Tuesday with the release of Sentry R10.5.2, R10.6.2, and R10.7.1. At the time of disclosure, the company said it was not aware of any customer exploitation.

That changed quickly.

The nonprofit security organization Shadowserver reported the following day that attackers were already attempting to exploit the vulnerability using a public proof-of-concept exploit. Shadowserver also warned that exposed Ivanti Sentry instances were likely already compromised if they had not been patched.

According to Shadowserver, its scans detected 19 vulnerable Ivanti Sentry instances, with at least two confirmed as backdoored. The organization cautioned that the number of exposed systems may be undercounted because some Ivanti Sentry deployments were not reachable by its scans, possibly due to blocklisting or limited visibility.

Shadowserver’s warning was blunt: organizations that had not patched internet-facing Ivanti Sentry systems should assume compromise is likely.

The risk is significant because successful exploitation allows attackers to execute code with root privileges. On a secure mobile gateway, root access can give threat actors deep control over the appliance and potentially provide a foothold into the broader enterprise network.

Security appliances are high-value targets because they often sit at the edge of corporate environments, process sensitive traffic, and maintain trusted access to internal systems. When attackers compromise these devices, they can use them for persistence, traffic interception, credential theft, lateral movement, and further intrusion activity.

Ivanti’s original advisory has not yet been updated to reflect active exploitation. The advisory still states that the company was not aware of customer exploitation at the time of disclosure.

Ivanti products have been repeatedly targeted by threat actors in recent years because vulnerabilities in edge security and mobile management appliances can provide direct access into enterprise networks. Multiple Ivanti flaws have previously been exploited as zero-days, including vulnerabilities affecting Endpoint Manager Mobile, or EPMM, that were used against a limited number of customers before patches were released.

U.S. federal agencies have also been ordered by the Cybersecurity and Infrastructure Security Agency to patch Ivanti systems in response to actively exploited vulnerabilities. Over the past several years, CISA has flagged dozens of Ivanti vulnerabilities as exploited in the wild, with several also linked to ransomware activity.

For organizations running Ivanti Sentry, immediate action is recommended. Administrators should upgrade to R10.5.2, R10.6.2, or R10.7.1 as soon as possible, depending on their deployed branch.

However, patching alone may not be enough if the system was exposed while vulnerable. Because exploitation is now being observed in the wild and backdoors have already been detected on some systems, organizations should treat unpatched internet-facing appliances as potentially compromised.

Recommended response steps include removing unnecessary internet exposure, applying the latest Ivanti Sentry update, reviewing the appliance for unauthorized changes, checking for suspicious files or backdoors, rotating credentials that may have passed through or been stored on the system, and reviewing logs for evidence of command execution or unusual outbound connections.

Security teams should also monitor for post-exploitation behavior, including new user accounts, modified configuration files, unexpected network connections, suspicious processes, and attempts to pivot from the Sentry appliance into internal systems.

The exploitation of CVE-2026-10520 reinforces a broader security trend: attackers continue to prioritize edge appliances because they provide high-impact access with limited user interaction. For enterprises, any internet-facing security gateway should be treated as critical infrastructure and patched with urgency when remote code execution or command injection flaws are disclosed.

Aaron Fare
More from this author

Aaron Fare

View this author’s public articles and updates.

View author profile →
Discussion

Comments

0 public comments

No comments yet

Be the first to add a comment to this article.

Add a comment

Sign In