Ivanti Sentry pre-auth RCE (CVE-2026-10520) – CVSS 10.0, public PoC, CISA KEV

A critical pre-authentication remote code execution vulnerability (CVE-2026-10520) has been identified in Ivanti Sentry appliances. The flaw allows unauthenticated attackers to gain root-level access, and it is currently being exploited in the wild.
Why it matters
As Ivanti Sentry is used to secure enterprise traffic, this vulnerability poses a severe risk to corporate network security and requires immediate patching.
Ivanti Sentry (formerly MobileIron Sentry) contains a pre-authentication OS command injection vulnerability that gives remote attackers root-level code execution. CVSS 10.0, actively exploited in the wild, CISA KEV listed with a 3-day remediation deadline. A public PoC is available from watchTowr Labs. Here's how to find Ivanti Sentry appliances on your network.
The content is a technical security advisory based on CVE data and industry reports.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in