🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Ivanti Sentry OS Command Injection RCE (CVE-2026-10520) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 12, 2026
CVECVE-2026-10520
CVSS Score10.0
Affectedstandalone_sentry
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has issued a binding directive requiring federal agencies to patch CVE-2026-10520 in Ivanti Sentry by Sunday, a maximum-severity OS command injection flaw in the Ivanti Sentry security gateway appliance. Shadowserver confirmed active backdooring of exposed Sentry instances within 24 hours of a public proof-of-concept dropping, and states that any unpatched internet-exposed instance should be treated as already compromised. The attack chain allows remote command execution without authentication, meaning an attacker does not need credentials to own the box.
⚠️Why It Matters for MSSPs
If any of your clients are running Ivanti Sentry as a mobile device management gateway or network access control layer, that appliance is a direct bridge into their internal network and you have a 24-hour window before the assumption shifts from possible compromise to confirmed compromise. On your own stack, if you use Ivanti products anywhere in your remote access or MDM toolchain, you are a high-value target because owning your gateway means owning every client behind it.
✅Recommended Action
Pull your asset inventory right now, identify every Ivanti Sentry instance across your own environment and every client environment you manage, apply the vendor patch released this week immediately, and send a written advisory to all clients today documenting the threat, your remediation steps, and any exposure findings so your obligation is on record.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.