🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Ivanti Sentry OS Command Injection RCE (CVE-2026-10520) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 11, 2026
CVECVE-2026-10520
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-10520, an OS command injection flaw in Ivanti Sentry, to the Known Exploited Vulnerabilities catalog, meaning active exploitation is already underway before this bulletin reached your inbox. An unauthenticated remote attacker can achieve root-level code execution on any Sentry appliance with externally reachable endpoints. The June 14 patch deadline is a compliance floor, not a safe timeline to wait for.
⚠️Why It Matters for MSSPs
If you or any of your clients run Ivanti Sentry for mobile device management, that appliance is a direct entry point into the network it manages, and root-level RCE means an attacker owns the device and everything it touches. Your own stack is at risk if you use Sentry to manage endpoints across client environments, because one compromised appliance hands an attacker lateral movement into every tenant you support. If a client gets hit through an unpatched Sentry instance and you had not flagged this advisory, that is a retention conversation you do not want to have.
✅Recommended Action
In the next 24 hours, audit every Sentry deployment across your own infrastructure and your full client base to confirm whether endpoints are externally reachable and whether mTLS or Neurons for MDM access restrictions are in place. Any appliance that is internet-exposed and unmanaged gets patched or taken offline today, not by June 14. Send a direct client notification this afternoon to every account running Ivanti Sentry so they cannot later claim they were not warned.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.