INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ivanti Sentry Gateways Exploited by CVE-2026-10520

| 2026-06-11 17:57 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is increasingly complex, with multiple vulnerabilities exploited by attackers targeting Ivanti Sentry gateways. The critical CVE-2026-10520 flaw in these secure gateway appliances allows remote code execution with root privileges, compromising internet-exposed gateways shortly after patches were released. This has already led to the discovery of backdoored (i.e., compromised) instances and exploitation attempts by researchers at Shadowserver. Ivanti Sentry acts as a critical component within enterprise environments, providing a gateway between mobile devices and internal corporate systems. As CISA continues to add multiple actively exploited vulnerabilities to its KEV catalog, including CVE-2026-1340 affecting Endpoint Manager Mobile and CVE-2026-1603 affecting Endpoint Manager, the risk of exploitation remains high.
Technical Mitigations AI-generated
• Implement a patch or update to Ivanti Sentry Gateways as soon as possible, ideally within the timeframe of shortly after patches were released. • Monitor gateways for signs of exploitation and take immediate action if any are found. • Ensure all users have up-to-date security updates and patches installed on their devices connected to Ivanti Sentry Gateways.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-10520CVE-2026-10520 CVE-2026-1340CVE-2026-1340 CVE-2026-1603CVE-2026-1603
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎January 2026
Threat actors exploited the Ivanti Sentry vulnerability CVE-2026-1340 in Gateways to target Endpoint Manager Mobile.
infrastructure Ivanti
vulnerability CVE-2026-1340
vulnerability CVE-2026-1603
attribution CISA
attribution KEV
attribution Endpoint
‎2026/06/11
Threat actors used a publicly disclosed vulnerability exploit in Ivanti Sentry gateways to target the affected software.
vulnerability CVE-2026-10520
infrastructure Ivanti
organisation Ivanti Sentry CVE-2026-10520
organisation PoC
‎2026/06/11
Threat actors exploited a maximum-severity OS command injection flaw in Ivanti Sentry, allowing remote code execution with root privileges.
organisation CVE-2026-10520
infrastructure Ivanti
organisation Ivanti Sentry Gateways Compromised Shortly
organisation Patch Release
organisation Ivanti Sentry
organisation IP
infrastructure 5.2
infrastructure 6.2
infrastructure 7.1
organisation An OS Command Injection
organisation Shadowserver
‎2026/06/12
Threat actors used Ivanti Sentry's CVE-2026-10520 vulnerability exploit to target Gateways.
vulnerability CVE-2026-10520
infrastructure Ivanti
organisation Ivanti Sentry CVE-2026-10520
organisation PoC
‎June 14, 2026
Threat actors exploited the Ivanti Sentry vulnerability in gateways to gain unauthorized access.
‎June 14
U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges Ivanti Sentry users to patch vulnerabilities by June 14 due to a known exploited flaw in the software.
infrastructure Ivanti
attribution Ivanti Sentry
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
Tactical Metrics
Metrics
infrastructure
‎Ivanti
Affected Product
Metrics
infrastructure
‎5.2
Software Version
Metrics
infrastructure
‎6.2
Software Version
Metrics
infrastructure
‎7.1
Software Version