INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ivanti Sentry Flaw Exploited Vulnerability Patching Required

| 2026-06-12 18:47 CRITICAL HIGH
Executive Summary AI-generated
The Ivanti Sentry flaw, tracked as CVE-2026-10520, has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. This critical vulnerability allows remote code execution with root privileges, posing a significant threat to organizations' internal systems and mobile devices. Researchers have identified active attacks on internet-exposed Sentry gateways, highlighting the need for prompt patching by June 14. Despite Ivanti's initial report of no evidence of active attacks, researchers continue to find backdoored gateways shortly after security updates were released. The vulnerability sits in a sensitive position within enterprise environments, making it an attractive target for threat actors.
Technical Mitigations AI-generated
* Implement a secure patching schedule for Ivanti Sentry, with a deadline of June 14, 2026. * Configure mTLS (mutual transport layer security) on EPMM-managed Sentry appliances to protect vulnerable APIs from remote code execution. * Ensure that MDM-managed Sentry appliances are not exposed to the internet and use secure management interfaces instead. * Monitor Ivanti Sentry instances for signs of exploitation and take action immediately if a threat is detected, such as blocking access to the management port 8443.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-10520CVE-2026-10520 CVE-2026-10523CVE-2026-10523 CVE-2026-1340CVE-2026-1340
Target & Sectors
SA
mediamedia governmentgovernment
Incident Timeline
‎2026/05/12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered the patching of Ivanti systems by June 14 due to a high-severity remote code execution flaw in Remote Code Execution Management Module (EPMM).
infrastructure Ivanti
tactic Remote Code Execution
attribution EPMM
‎2026/06/10
Cybersecurity vendor WatchTowr published a technical analysis of the Ivanti Sentry flaw, which was added to its Known Exploited Vulnerabilities catalog.
vulnerability CVE-2026-10520
organisation WatchTowr
infrastructure Ivanti
‎June 11, 2026
Ivanti discovered a CVE in its Sentry appliance management system using advanced language model (LLM) technology.
infrastructure Ivanti
organisation MDM
organisation API
organisation LLM
organisation CVE
organisation CVSS
‎Thursday, June 11
Threat actors used Ivanti Sentry flaw to target CISA.
infrastructure Ivanti
vulnerability CVE-2026-10520
organisation Security Affairs
‎2026/06/11
Ivanti Sentry's CVE-2026-10520 vulnerability was exploited in a large-scale attack.
infrastructure Ivanti
vulnerability CVE-2026-10520
organisation Ivanti Sentry CVE-2026-10520
industry Media
organisation the Shadowserver Foundation
organisation PoC
organisation BleepingComputer
‎2026/06/12
Threat actors used Ivanti Sentry to target vulnerable systems via CVE-2026-10520 exploits.
infrastructure Ivanti
vulnerability CVE-2026-10520
organisation Ivanti Sentry CVE-2026-10520
organisation PoC
‎2026/06/12
Threat actors exploited a maximum-severity vulnerability in Ivanti Sentry, a security gateway appliance that sits between an organization's internal systems and mobile devices.
infrastructure Ivanti
organisation Ivanti Sentry
infrastructure 5.2
infrastructure 6.2
infrastructure 7.1
organisation An OS Command Injection
organisation Shadowserver
organisation IP
organisation PoC
organisation Defused
organisation Unified Endpoint Management
organisation Ivanti Endpoint
organisation EPMM
organisation CVE-2026-10520
organisation BleepingComputer
organisation Nightmare-Eclipse Drops
organisation Another Microsoft Exploit
organisation RoguePlanet Risks to
victims 3,000 employees
victims 40,000 customers
organisation MobileIron Sentry
organisation CVSS
organisation NCA
organisation ShinyHunters
organisation Cybersecurity
organisation SOCRadar
organisation Bug Bounty Research Triggers
organisation EDR
financial 04 BOD
‎June 14, 2026
The U.S. CISA urges federal agencies to patch the Ivanti Sentry vulnerability by June 14, 2026.
‎June 14
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14.
infrastructure Ivanti
attribution Ivanti Sentry
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
Tactical Metrics
Metrics
infrastructure
‎Ivanti
Affected Product
Metrics
infrastructure
‎5.2
Software Version
Metrics
infrastructure
‎6.2
Software Version
Metrics
infrastructure
‎7.1
Software Version
Metrics
financial
4
Bod
Metrics
victims
3,000
Employees
Metrics
victims
40,000
Customers