CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2026-10520, an Ivanti Sentry OS command injection flaw, to its KEV Catalog after evidence of active exploitation.
Intelligence analysis by GPT-5.4 Mini
CISA says a newly identified Ivanti Sentry command injection vulnerability is being actively exploited, so it has been added to the Known Exploited Vulnerabilities Catalog. The agency is urging risk-based patching and notes federal agencies have stricter remediation duties under BOD 26-04.
CISA found a software weakness that bad actors are already using, like a back door someone has started testing in a house. It put that weakness on a priority list so people fix it fast before more damage happens.
Analysis
What CISA announced
CISA added one vulnerability to its Known Exploited Vulnerabilities Catalog on June 11, 2026: CVE-2026-10520, described as an Ivanti Sentry OS command injection vulnerability. CISA says the addition is based on evidence of active exploitation.
Why the KEV listing matters
CISA treats KEV entries as especially urgent because they are not just theoretical weaknesses. They are vulnerabilities with signs of real-world abuse, which means defenders should prioritize them over lower-risk issues. In this notice, CISA says this kind of flaw is a frequent attack path and can create significant risk for the federal enterprise.
Federal guidance and broader takeaway
The alert points to Binding Operational Directive 26-04, which updates earlier federal patching guidance and requires Federal Civilian Executive Branch agencies to prioritize fast remediation of high-risk vulnerabilities listed in the KEV Catalog on publicly exposed assets that can lead to total control after exploitation. The notice also says agencies should check whether threat actors compromised the system before the patch was applied when required by the directive.
Although the directive applies only to FCEB agencies, CISA explicitly encourages all organizations to use risk-based vulnerability management and to prioritize KEV-listed issues. The agency also says it will keep adding vulnerabilities that meet its criteria and invites nominations for exploited vulnerabilities that are not yet listed, provided they have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Key points
- CISA added CVE-2026-10520, an Ivanti Sentry OS command injection flaw, to the KEV Catalog.
- The listing is based on evidence of active exploitation.
- CISA says the vulnerability is a frequent attack vector and can pose significant risk.
- BOD 26-04 requires U.S. federal civilian agencies to prioritize rapid remediation of KEV-listed vulnerabilities.
- CISA urges all organizations to use risk-based vulnerability management and prioritize KEV items.
If organizations act quickly on the KEV listing, they can reduce the chance that this Ivanti flaw is used against them. The notice also gives defenders a clear signal to focus limited time and resources on a confirmed threat.
If organizations ignore the alert or delay patching, attackers may keep exploiting exposed systems. The risk is higher for systems that are publicly reachable or not checked for compromise before the fix was applied.



