Article may be outdated

This article is 72 days old. Some details may have changed since publication.

Hacker News·3 min read·hard

Ivanti Sentry pre-auth RCE (CVE-2026-10520) – CVSS 10.0, public PoC, CISA KEV

S
slvnx
Ivanti Sentry pre-auth RCE (CVE-2026-10520) – CVSS 10.0, public PoC, CISA KEV
AI Summary

A critical pre-authentication remote code execution vulnerability (CVE-2026-10520) has been identified in Ivanti Sentry appliances. The flaw allows unauthenticated attackers to gain root-level access, and it is currently being exploited in the wild.

Why it matters

As Ivanti Sentry is used to secure enterprise traffic, this vulnerability poses a severe risk to corporate network security and requires immediate patching.

Dive DeeperCreate a free account to unlock

Ivanti Sentry (formerly MobileIron Sentry) contains a pre-authentication OS command injection vulnerability that gives remote attackers root-level code execution. CVSS 10.0, actively exploited in the wild, CISA KEV listed with a 3-day remediation deadline. A public PoC is available from watchTowr Labs. Here's how to find Ivanti Sentry appliances on your network.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 95%

The content is a technical security advisory based on CVE data and industry reports.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in