Sunday, July 26, 2026 · Beirut, Lebanon Newsletter · About · Contact
Cybersecurity

Ivanti Sentry flaw scores 10.0 as attackers backdoor appliances

CVE-2026-10520 lets unauthenticated attackers gain root on Ivanti Standalone Sentry; researchers say exposed appliances are already being backdoored.

I
IT Magazine Staff July 10, 2026 · 1 min read
Cybersecurity

Ivanti has patched a maximum-severity vulnerability in its Standalone Sentry product after security researchers warned that internet-exposed appliances are already being compromised. CVE-2026-10520 is an OS command injection flaw (CWE-78) that carries a CVSS base score of 10.0 and allows a remote, unauthenticated attacker to achieve root-level remote code execution.

Sentry acts as a gateway between mobile devices and back-end enterprise resources such as email and application servers, so a full compromise hands an attacker a privileged foothold at the network edge. According to the Shadowserver Foundation, exposed Sentry instances are being actively backdoored, with attackers installing persistent access mechanisms on compromised systems.

The vulnerability affects Ivanti Standalone Sentry versions before 10.5.2, the 10.6.x branch before 10.6.2, and 10.7.0. Ivanti has released fixes in R10.5.2, R10.6.2 and R10.7.1, and the flaw has been added to CISA’s Known Exploited Vulnerabilities catalog. A second issue disclosed alongside it, CVE-2026-10523, was addressed in the same updates.

Because the flaw requires no credentials and yields root, organisations running Sentry should treat any unpatched, internet-facing appliance as potentially compromised. The recommended response is to apply the vendor updates immediately, then hunt for backdoors, unexpected processes and unauthorised configuration changes rather than assuming a patch by itself closes the incident. Mobile-device gateways are a recurring target for state-aligned and criminal actors alike, which raises the stakes for enterprises across the region that rely on Ivanti for mobility management.

Sources: NVD: CVE-2026-10520 Ivanti Security Advisory

Drafted with AI assistance and reviewed by the IT Magazine news desk. Facts verified against the linked sources. Spotted an error? See our Corrections Policy.

Related stories